Rapid7 Vulnerability & Exploit Database

MFSA2009-68: Firefox NTLM Reflection Vulnerability

Back to Search

MFSA2009-68: Firefox NTLM Reflection Vulnerability

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
12/17/2009
Created
07/25/2018
Added
12/17/2009
Modified
02/13/2015

Description

Mozilla's NTLM implementation is vulnerable to reflection attacks in which NTLM credentials from one application could be forwarded to another arbitary application via the browser. If an attacker could get a user to visit a web page he controlled he could force NTLM authenticated requests to be forwarded to another application on behalf of the user.

Solution(s)

  • mozilla-firefox-upgrade-3_5_6
  • mozilla-firefox-upgrade-3_0_16

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;