CVE-2019-11708 is an insufficient validation vulnerability in Firefox and Thunderbird's handling of parameters supplied in the Prompt:Open IPC message. A compromised sandboxed child process can cause the non-sandboxed parent process to open attacker-selected web content, crossing the intended process-sandbox trust boundary. It affects Firefox before 67.0.4, Firefox ESR before 60.7.2, and Thunderbird before 60.7.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains a short README and one 56 KB self-contained HTML/JavaScript exploit. `exploit.html` implements a staged browser-to-SYSTEM chain: it parses stage/run/retry parameters, performs low-level JavaScript memory manipulation consistent with an IonMonkey native-code-execution attempt for CVE-2019-11707, and uses a privileged `Prompt:Open` message path intended to reach the Firefox parent process (CVE-2019-11708). It then includes a large Base64-embedded Donut x64 payload described as a CVE-2021-1732 Windows privilege-escalation executable. The stated final action is an elevated `cmd.exe /k whoami` command prompt. It has retry and pointer-drift checks, restores modified class pointers on exceptions, and contains optional localhost-only hold/signaling instrumentation; it does not require external exploit hosting, fixed module bases, or profile modifications according to its comments. The README only links to external research and a demonstration video.
This repository contains a full browser exploit chain targeting Mozilla Firefox on Windows 64-bit, specifically exploiting CVE-2019-9810 (IonMonkey JIT bug) and CVE-2019-11708 (sandbox escape via Prompt:Open IPC message). The main exploit logic is implemented in JavaScript (cthulhu.js, ff-toolbox.js) and is launched via index.html. The exploit achieves arbitrary code execution in both the content and parent (broker) processes of Firefox, ultimately escaping the browser sandbox. After successful exploitation, it drops and executes a Windows payload (payload.exe), which creates multiple animated, transparent windows on the desktop as a demonstration of code execution. Additionally, the exploit injects a privileged JavaScript frame script into all browser tabs, effectively backdooring the browser for further arbitrary JS execution. The payload is built from C++ source (payload/src/payload.cc) and uses GDI for graphical effects. The repository is well-documented, with detailed build instructions and references to the relevant CVEs and Mozilla bug reports. The exploit is operational and demonstrates a full chain from browser compromise to system-level code execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.