Improper input validation in Mozilla Firefox - CVE-2018-12368
Published: June 27, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to iWindows 10 does not warn users before opening executable files with the SettingContent-msextension even when they have been downloaded from the internet and have the "Mark of the Web". A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, use WebExtension with the limited downloads.openpermission and execute arbitrary code without user interaction on Windows 10 systems
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Firefox ESR
Gentoo Linux
Slackware Linux
Mozilla Thunderbird
How to mitigate CVE-2018-12368
Mozilla Thunderbird - update to 60.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Firefox ESR
- Multiple vulnerabilities in Mozilla Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird
- Multiple vulnerabilities in Mozilla Thunderbird
- Gentoo update for Mozilla Firefox