Spoofing attack in Mozilla Firefox - CVE-2019-11696
Published: May 21, 2019
Mozilla Firefox
Detailed vulnerability description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of .JNLP files that are not recognized as executable files. A remote attacker can trick the victim into downloading and running a malicious Java web start file and execute arbitrary Java code on the system.
Successful exploitation of the vulnerability requires that Java is installed on the system.