vendor:
Firefox
by:
SIGAINT
9,3
CVSS
HIGH
Memory Corruption Vulnerability
119
CWE
Product Name: Firefox
Affected Version From: Firefox version 41
Affected Version To: Firefox version 50
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
TOR Browser 0day : JavaScript Exploit !
This is an Javascript exploit actively used against TorBrowser NOW. It consists of one HTML and one CSS file, both pasted below and also de-obscured. The exact functionality is unknown but it's getting access to 'VirtualAlloc' in 'kernel32.dll' and goes from there. It leverages a memory corruption vulnerability in the background to make direct calls to kernel32.dll, which allows malicious code to be executed on computers running Windows and makes redirect to '/member.php' after code execution.
Mitigation:
Disable Javascript in the browser, update the browser to the latest version, and use a firewall to block malicious traffic.