Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party application that insufficiently sanitized URL data. In that situation, clicking a link in the third party application could have been used to retrieve and execute files whose location was supplied through command line arguments. Note: This issue only affects Windows operating systems and when Firefox is configured as the default handler for non-default filetypes. Other operating systems are unaffected. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Aug 22, 2024 | Mar 2, 2020 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Mar 13, 2020 | Mar 2, 2020 |
| Mfsa2020 05 | — | Upgrade to Mozilla Firefox version 73.0Upgrade to the latest version of Mozilla Firefox | Feb 12, 2020 | Feb 11, 2020 |
| Mfsa2020 06 | — | Upgrade to Mozilla Firefox ESR version 68.5Upgrade to the latest version of Mozilla Firefox | Mar 11, 2020 | Mar 2, 2020 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 68.5.0-11.4.19.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.5.0-11.4.19.0.1.2.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.5.0-11.4.19.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird to version 68.5.0-11.4.19.0.1.2.0 on Solaris 11.4 | Jan 19, 2021 | Mar 2, 2020 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade mozillafirefox-buildsymbolsUpgrade MozillaFirefox-develUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-other | Feb 18, 2020 | Feb 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub