Уязвимость запуска страниц и выполнения скриптов в Internet Explorer через "mk" схему в Firefox на Windows
Описание
При передаче навигации операционной системе Firefox принимает mk схему, что позволяет злоумышленникам запускать страницы и выполнять скрипты в Internet Explorer в непривилегированном режиме.
Примечание: эта уязвимость затрагивает только Firefox для Windows. Другие операционные системы не затрагиваются.
Затронутые версии ПО
- Firefox версий ниже 92
- Thunderbird версий ниже 91.1
- Thunderbird версий ниже 78.14
- Firefox ESR версий ниже 78.14
- Firefox ESR версий ниже 91.1
Тип уязвимости
- Запуск страниц
- Выполнение скриптов
Ссылки
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
When delegating navigations to the operating system, Firefox would acc ...
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2