CVE-2021-38492Inclusion of Functionality from Untrusted Control Sphere in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 38.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3
Latest updateMay 24

Description

When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified92
NVDmozilla/firefox91.091.1+1
CVEListV5mozilla/firefox_esrunspecified78.14+1
NVDmozilla/firefox_esr< 78.14
CVEListV5mozilla/thunderbirdunspecified91.1+1

🔴Vulnerability Details

3
GHSA
GHSA-qq3m-5g62-2hhj: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri2022-05-24
OSV
CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri2021-11-03
CVEList
CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scri2021-11-03

📋Vendor Advisories

7
Red Hat
Mozilla: Navigating to `mk:` URL scheme could load Internet Explorer2021-09-07
Debian
CVE-2021-38492: firefox - When delegating navigations to the operating system, Firefox would accept the `m...2021
Mozilla
Mozilla Foundation Security Advisory 2021-41: CVE-2021-38492
Mozilla
Mozilla Foundation Security Advisory 2021-40: CVE-2021-38492
Mozilla
Mozilla Foundation Security Advisory 2021-39: CVE-2021-38492
CVE-2021-38492 — Mozilla Firefox vulnerability | cvebase