Rule Category

BROWSER-FIREFOX -- Snort has detected traffic known to exploit vulnerabilities present in the Firefox browser, or products that have the "Gecko" engine (Thunderbird email client, etc.).

Alert Message

BROWSER-FIREFOX Mozilla Firefox default content process DACL sandbox escape attempt

Rule Explanation

This rule looks for a crafted Windows executable that will exploit a Firefox sandbox escape vulnerability.

What To Look For

This rule looks for an attempt to exploit a Mozilla Firefox sandbox escape vulnerability.

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

MITRE ATT&CK Framework

Tactic: Execution

Technique: Exploitation for Client Execution

For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org

Additional Links

Rule Vulnerability

N/A

Not Applicable

CVE Additional Information