Urgent parking before public exploits on Firefox Chrome and Adobe to avoid intrusions

Author: Published 3 min de lectura 177 reading

The images in this article were generated with artificial intelligence. How we publish

Mozilla and Google published this week critical patches that correct vulnerabilities that can be exploited to run code or corrupt memory on browsers, and Adobe released a new series of updates that fix dozens of high-gravity failures in server and desktop products. The most urgent news is that Mozilla warned that there is already public explosion code for one of the failures in Firefox, so the risk window for unpatched users has been significantly shortened.

In the case of Firefox, the corrections are included in version 152.0.6 and refer to problems in the JavaScript / WebAssembly engine and in site isolation in the DOM; Mozilla confirmed that there is public operating evidence although, for now, they have not detected targeted attacks in nature. Google, on the other hand, solved 15 Chrome failures, including two critical user--after-free in Ozone - the abstraction layer of inputs and graphics on platforms such as Linux and ChromeOS - that could result in memory corruption if a user makes UI gestures induced by a malicious page.

Urgent parking before public exploits on Firefox Chrome and Adobe to avoid intrusions
Image generated with IA.

Adobe reported and patched 88 vulnerabilities in products such as ColdFusion, Commerce, Experience Manager and Illustrator; several of the failures in ColdFusion and on trade platforms have CVSS scores close to 10 and allow from traversal routes and SQL injection to remote code execution without authentication. A Broadcom update was also published for a VMware authentication vulnerability Avi Load Balancer that allows access to the control plane with network access.

The implications for organizations are clear: if you have exposed services - user browsers, ColdFusion servers, trading platforms or balancing - you must act today. The attackers are often quick to take advantage of public exploits and the failures in highly deployed software are preferred for mass campaigns or for post-exploitation in targeted intrusions. In addition, failures in infrastructure components (balers, content managers, ecommerce platforms) can allow for climbing and lateral movement within corporate networks.

Urgent parking before public exploits on Firefox Chrome and Adobe to avoid intrusions
Image generated with IA.

If you manage affected assets, prioritize the parking: display Firefox 152.0.6 in endpoints, update Chrome to the versions that correct the reported CVE (the branches 150.7871.124 / .125 according to platform) and apply the Adobe updates for ColdFusion, Commerce and OEM mentioned by the manufacturer. If you cannot park immediately, implement compensatory controls such as restricting access to IP administrative interfaces, placing critical applications behind a Web Application Firewall with rules for armored uploads and SSRF, and segmenting the network to limit the scope of a possible intrusion. Also maintain enhanced detection: review access logs, monitor abnormal behaviors and activate alerts for known operating patterns.

In parallel to the technical response, use this episode to strengthen processes: software inventory and dependencies, exposure-based prioritization and CVSS / business impact, regression tests in controlled environments and fast deployment procedures for hotfixes. Do not forget to coordinate with support and communication equipment to inform end users about the need to update browsers and avoid downloading content or performing unknown gestures on unreliable pages.

To check official security notices and verify versions and mitigation, check the manufacturers' pages and vulnerability databases: Mozilla Security Notices, Adobe Security Centre and the NIST vulnerability database in nvd.nist.gov. Adopting a faster patching cycle and compensatory controls will directly reduce the likelihood that a known failure will be exploited in your environment.

Coverage

Related

More news on the same subject.