Security restrictions bypass in Mozilla Firefox - CVE-2018-5174
Published: May 10, 2018
Vulnerability identifier: #VU12563
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5174
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to the Windows Defender SmartScreen UI runs with less secure behavior for downloaded files. A remote attacker can bypass security restrictions and perform further attack.
Affected software
Mozilla Firefox
Firefox ESR
SUSE Linux
openSUSE Leap
Mozilla Thunderbird
Firefox ESR
SUSE Linux
openSUSE Leap
Mozilla Thunderbird
How to mitigate CVE-2018-5174
Update to version 60.0.