#VU72253 Out-of-bounds read in Mozilla Firefox and Firefox ESR - CVE-2023-25738
Published: February 15, 2023
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a missing validation of members of the DEVMODEW struct set by the printer device driver while printing web page in Windows. A remote attacker can trick the victim to print a specially crafted web page and crash the browser.
Note, the vulnerability affects Windows installations only.