CVE-2021-38492
published 2021-11-03CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.12%
62.8th percentile
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 92.0 | 92.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 91.0 < 91.1 | 91.1 |
| mozilla | firefox | >= unspecified < 92 | 92 |
| mozilla | firefox_esr | < 78.14 | 78.14 |
| mozilla | firefox_esr | >= unspecified < 78.14 | 78.14 |
| mozilla | firefox_esr | >= unspecified < 91.1 | 91.1 |
| mozilla | thunderbird | < 78.14 | 78.14 |
| mozilla | thunderbird | >= 91.0 < 91.1 | 91.1 |
| mozilla | thunderbird | >= unspecified < 91.1 | 91.1 |
| mozilla | thunderbird | >= unspecified < 78.14 | 78.14 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qq3m-5g62-2hhj: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri
ghsa_unreviewed·2022-05-24
CVE-2021-38492 [MEDIUM] GHSA-qq3m-5g62-2hhj: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
OSV
CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri
osv·2021-11-03·CVSS 6.5
CVE-2021-38492 [MEDIUM] CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
Red Hat
Mozilla: Navigating to `mk:` URL scheme could load Internet Explorer
vendor_redhat·2021-09-07·CVSS 6.5
CVE-2021-38492 [MEDIUM] CWE-829 Mozilla: Navigating to `mk:` URL scheme could load Internet Explorer
Mozilla: Navigating to `mk:` URL scheme could load Internet Explorer
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
P
Debian
CVE-2021-38492: firefox - When delegating navigations to the operating system, Firefox would accept the `m...
vendor_debian·2021·CVSS 6.5
CVE-2021-38492 [MEDIUM] CVE-2021-38492: firefox - When delegating navigations to the operating system, Firefox would accept the `m...
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2021-41: CVE-2021-38492
vendor_mozilla·CVSS 6.5
CVE-2021-38492 [MEDIUM] Mozilla Foundation Security Advisory 2021-41: CVE-2021-38492
Mozilla Foundation Security Advisory 2021-41
CVE: CVE-2021-38492
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.1
Mozilla
Mozilla Foundation Security Advisory 2021-40: CVE-2021-38492
vendor_mozilla·CVSS 6.5
CVE-2021-38492 [MEDIUM] Mozilla Foundation Security Advisory 2021-40: CVE-2021-38492
Mozilla Foundation Security Advisory 2021-40
CVE: CVE-2021-38492
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 91.1
Mozilla
Mozilla Foundation Security Advisory 2021-39: CVE-2021-38492
vendor_mozilla·CVSS 6.5
CVE-2021-38492 [MEDIUM] Mozilla Foundation Security Advisory 2021-39: CVE-2021-38492
Mozilla Foundation Security Advisory 2021-39
CVE: CVE-2021-38492
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.14
Mozilla
Mozilla Foundation Security Advisory 2021-42: CVE-2021-38492
vendor_mozilla·CVSS 6.5
CVE-2021-38492 [MEDIUM] Mozilla Foundation Security Advisory 2021-42: CVE-2021-38492
Mozilla Foundation Security Advisory 2021-42
CVE: CVE-2021-38492
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.14
Mozilla
Mozilla Foundation Security Advisory 2021-38: CVE-2021-38492
vendor_mozilla·CVSS 6.5
CVE-2021-38492 [MEDIUM] Mozilla Foundation Security Advisory 2021-38: CVE-2021-38492
Mozilla Foundation Security Advisory 2021-38
CVE: CVE-2021-38492
Product: Firefox
Impact: high
Fixed in: Firefox 92
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1721107https://security.gentoo.org/glsa/202208-14https://www.mozilla.org/security/advisories/mfsa2021-38/https://www.mozilla.org/security/advisories/mfsa2021-39/https://www.mozilla.org/security/advisories/mfsa2021-40/https://www.mozilla.org/security/advisories/mfsa2021-41/https://www.mozilla.org/security/advisories/mfsa2021-42/https://bugzilla.mozilla.org/show_bug.cgi?id=1721107https://security.gentoo.org/glsa/202208-14https://www.mozilla.org/security/advisories/mfsa2021-38/https://www.mozilla.org/security/advisories/mfsa2021-39/https://www.mozilla.org/security/advisories/mfsa2021-40/https://www.mozilla.org/security/advisories/mfsa2021-41/https://www.mozilla.org/security/advisories/mfsa2021-42/
2021-11-03
Published