vendor:
Pale Moon
by:
Berk Cem Goksel
9.8
CVSS
CRITICAL
Use After Free
416
CWE
Product Name: Pale Moon
Affected Version From: 27.9.0
Affected Version To: 27.9.2
Patch Exists: YES
Related CWE: CVE-2018-12292
CPE: a:moonchild_productions:pale_moon
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
This exploit is a proof of concept for a Use After Free vulnerability in Pale Moon Browser versions prior to 27.9.3. The vulnerability is triggered when the SetVariable() function is called with a NodeList object as the first argument. This causes a Use After Free condition, which can be used to execute arbitrary code.
Mitigation:
Users should update to the latest version of Pale Moon Browser (27.9.3 or later) to mitigate this vulnerability.