#VU20817 OS Command Injection in Mozilla Firefox - CVE-2019-11751
Published: September 3, 2019
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper sanitization of logging-related command line parameters, when launching Firefox from another application. A remote attacker can create a specially crafted link, trick the victim to click on the link within an external application (e.g. messenger application) and write a log file to arbitrary location on the system, such as "Startup" folder. As a result a remote attacker can execute arbitrary code on the system.