CVE-2019-9801 — Improper Input Validation in Mozilla Firefox
Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 26
Latest updateMay 24
Description
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages9 packages
🔴Vulnerability Details
2GHSA▶
GHSA-cr8h-fffv-pv55: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on↗2022-05-24
OSV▶
CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on↗2019-04-26
📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2019-9801 Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content↗2019-03-20