Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-9791 PoC — Mozilla Firefox和Firefox ESR 输入验证错误漏洞

Source
Associated Vulnerability
Title: Mozilla Firefox和Firefox ESR 输入验证错误漏洞 (CVE-2019-9791)
Description:The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Description
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
Readme
# Exploit chain for CVE-2019-9791 & CVE-2019-11708 against Firefox 65.0 

Works against Firefox 65.0 on windows 64bit.  CVE-2019-11708 part is taken from exploit by 0vercl0k:

https://github.com/0vercl0k/CVE-2019-11708

The exploit uses CVE-2019-9791 to obtain read/write primitive in content process then CVE-2019-11708 to make the main process load arbitrary url. In parent process  CVE-2019-9791 is used again to obtain arbitrary code execution.



![](demo.gif)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →