CVE-2021-38492 Information

Description

When delegating navigations to the operating system Firefox would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 92 Thunderbird < 91.1 Thunderbird < 78.14 Firefox ESR < 78.14 and Firefox ESR < 91.1.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

https://www.mozilla.org/security/advisories/mfsa2021-41/ https://www.mozilla.org/security/advisories/mfsa2021-40/ https://www.mozilla.org/security/advisories/mfsa2021-42/ https://www.mozilla.org/security/advisories/mfsa2021-38/ https://www.mozilla.org/security/advisories/mfsa2021-39/ https://bugzilla.mozilla.org/show_bug.cgi?id=1721107

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: