Endpoint Vulnerability

Privilege escalation through internal workers

Description

Mozilla community member Jonas Jenwald reported broken behavior in Mozilla's PDF.js PDF file viewer which led to the discovery that internal Workers were incorrectly executed with high privilege. If this flaw were combined with a separate vulnerability allowing for same-origin policy violation, it could be used to run arbitrary code.

Affected Products

Firefox ESR

References

CVE-2015-2743,