Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-46875

 

Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2022-46875

Published: December 13, 2022 / Updated: January 16, 2023


Vulnerability identifier: #VU70148
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2022-46875
CWE-ID: CWE-357
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Affected software:
Mozilla Firefox
Firefox ESR
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Workstation Extension
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
mozilla-thunderbird
mozilla-firefox
MozillaFirefox
MozillaFirefox-debuginfo
MozillaFirefox-debugsource
MozillaFirefox-devel
MozillaFirefox-translations-common
MozillaFirefox-translations-other
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
MozillaThunderbird-debugsource
MozillaThunderbird-debuginfo
MozillaThunderbird
MozillaFirefox-branding-upstream
mail-client/thunderbird
mail-client/thunderbird-bin
www-client/firefox
Mozilla Thunderbird
Synthetic Playback Agent

Detailed vulnerability description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to executable file warning is not displayed when downloading .atloc and .ftploc files. A remote attacker can trick the victim into downloading and executing dangerous files.

Note, the vulnerability affects macOS installations only.


How to mitigate CVE-2022-46875

Install updates from vendor's website.

Sources