Security features bypass in Mozilla Firefox - CVE-2023-25740

 

Security features bypass in Mozilla Firefox - CVE-2023-25740

Published: February 15, 2023


Vulnerability identifier: #VU72258
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25740
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when handling .scf scrips that are opened by the browser from the local filesystem. A remote attacker can trick the victim into launching a specially crafted .scf script that then initiates network requests from the operating system to the malicious server. A remote attacker can obtain potentially sensitive information including NTLM credentials.

Note, the vulnerability affects Windows installations only.

Affected software

Mozilla Firefox
Gentoo Linux
Firefox for Android
Firefox Focus for Android
mail-client/thunderbird
mail-client/thunderbird-bin

How to mitigate CVE-2023-25740

Install updates from vendor's website.

Mozilla Firefox - update to 110.0
Firefox for Android - update to 110.0
Firefox Focus for Android - update to 110.0.1
mail-client/thunderbird - update to 102.10.0
mail-client/thunderbird-bin - update to 102.10.0

External References

Related Security Bulletins