
This a manual exploit of https://www.exploit-db.com/exploits/41151, another one exists for Windows 10 (https://github.com/soham23/firefox-rce-nssmil) but it didn't work on windows 8.1 so I made mine.
You have to modify the line 241 with your own shellcode. There is an example above this line.
Download the repository, and start a server. Using python server works fine.
python3 -m http.server 8080
On your victime browse to http://<attacker_ip>:8080/ and it should work.
Tested on Windows 8.1 Entreprise x64 using firefox 38.