Back

CVE-2020-12389

CRITICAL

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

Published: May 26, 2020 Modified: Jun 17, 2026
CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
mozilla firefox * < 76.0
mozilla firefox_esr * < 68.8.0

GitHub Security Advisory GHSA-hgp4-9j3m-3phf

The Firefox content processes did not sufficiently lockdown access control which could result in...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 1.73%

Top 24% most likely to be exploited

Threat Score 40.5 / 100

Data Sources

NVD EPSS GitHub