# Exploit Title: Mozilla Firefox 67 - Array.pop JIT Type Confusion # Date: 2021-12-07 # Type: RCE # Platform: Windows # Exploit Author: deadlock (Forrest Orr) # Author Homepage: https://forrest-orr.net # Vendor Homepage: https://www.mozilla.org/en-US/ # Software Link: https://ftp.mozilla.org/pub/firefox/releases/65.0.1/win64/en-US/ # Version: Firefox 67.0.2 64-bit and earlier # Tested on: Windows 10 x64 # CVE: CVE-2019-11707 # Bypasses: DEP, High Entropy ASLR, CFG # Full Hydseven exploit chain with sandbox escape (CVE-2019-11708): https://github.com/forrest-orr/Exploits/tree/main/Chains/Hydseven