CVE-2010-3765
9.5 CISA KEVMozilla · Firefox, Thunderbird, SeaMonkey
A memory corruption vulnerability in Mozilla products allows unauthenticated remote attackers to execute arbitrary code via crafted JavaScript content.
Executive summary
This critical remote code execution vulnerability in multiple Mozilla products is confirmed to be actively exploited in the wild and requires immediate remediation.
Vulnerability
This is a memory corruption vulnerability triggered when JavaScript is enabled, involving the nsCSSFrameConstructor::ContentAppended function and the appendChild method. It allows an unauthenticated attacker to execute arbitrary code on the host system.
Business impact
The CVSS score of 9.5 classifies this as a critical vulnerability. Successful exploitation permits full system compromise, enabling attackers to execute malicious payloads, such as the Belmoo malware, which can lead to complete loss of data confidentiality, integrity, and availability. The historical use of this exploit against high profile targets demonstrates its severe potential for reputational damage and organizational disruption.
Remediation
Immediate Action: Update to the patched versions: Firefox 3.5.15, Firefox 3.6.12, Thunderbird 3.0.11, Thunderbird 3.1.7, or SeaMonkey 2.0.11.
Proactive Monitoring: Review system logs for unauthorized binary execution or unexpected network connections associated with known malicious domains or the Belmoo malware family.
Compensating Controls: Disable JavaScript in affected browsers as a temporary measure to prevent the triggering of the vulnerable code path until patches can be deployed.
Exploitation status
Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.
Analyst recommendation
Given the critical severity and confirmed history of active exploitation, immediate patching is mandatory for all affected systems. Organizations must prioritize upgrading to the specified patched versions to eliminate the risk of remote code execution and subsequent malware infection.
More Mozilla CVEs
Sources
- 44425 Vulnerability database entry
- RHSA-2010:0812 Vendor advisory
- bugzilla.mozilla.org
- ADV-2010-2837 Vulnerability database entry
- bugzilla.redhat.com
- support.avaya.com
- 41965 Third-party advisory
- 41975 Third-party advisory