When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade linux-thunderbirdUpgrade seamonkeyUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade waterfoxUpgrade firefoxUpgrade libxul | Dec 12, 2018 | Dec 11, 2018 |
| Mfsa2018 29 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 64.0 | Dec 12, 2018 | Dec 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub