CVE-2021-38505
published 2021-12-08CVE-2021-38505: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.05%
60.4th percentile
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 94.0 | 94.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 94 | 94 |
| mozilla | firefox_esr | < 91.3.0 | 91.3.0 |
| mozilla | firefox_esr | >= unspecified < 91.3 | 91.3 |
| mozilla | thunderbird | < 91.3.0 | 91.3.0 |
| mozilla | thunderbird | >= unspecified < 91.3 | 91.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw34-2587-pprf: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, an
ghsa_unreviewed·2021-12-09
CVE-2021-38505 [MEDIUM] CWE-668 GHSA-fw34-2587-pprf: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, an
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
OSV
CVE-2021-38505: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, an
osv·2021-12-08·CVSS 6.5
CVE-2021-38505 [MEDIUM] CVE-2021-38505: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, an
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Red Hat
Mozilla: Windows 10 Cloud Clipboard may have recorded sensitive user data
vendor_redhat·2021-11-02·CVSS 6.5
CVE-2021-38505 [MEDIUM] CWE-838 Mozilla: Windows 10 Cloud Clipboard may have recorded sensitive user data
Mozilla: Windows 10 Cloud Clipboard may have recorded sensitive user data
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
The Mozilla Foundation Security Advis
Debian
CVE-2021-38505: firefox - Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which,...
vendor_debian·2021·CVSS 6.5
CVE-2021-38505 [MEDIUM] CVE-2021-38505: firefox - Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which,...
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2021-50: CVE-2021-38505
vendor_mozilla·CVSS 6.5
CVE-2021-38505 [MEDIUM] Mozilla Foundation Security Advisory 2021-50: CVE-2021-38505
Mozilla Foundation Security Advisory 2021-50
CVE: CVE-2021-38505
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.3
Mozilla
Mozilla Foundation Security Advisory 2021-48: CVE-2021-38505
vendor_mozilla·CVSS 6.5
CVE-2021-38505 [MEDIUM] Mozilla Foundation Security Advisory 2021-48: CVE-2021-38505
Mozilla Foundation Security Advisory 2021-48
CVE: CVE-2021-38505
Product: Firefox
Impact: high
Fixed in: Firefox 94
Mozilla
Mozilla Foundation Security Advisory 2021-49: CVE-2021-38505
vendor_mozilla·CVSS 6.5
CVE-2021-38505 [MEDIUM] Mozilla Foundation Security Advisory 2021-49: CVE-2021-38505
Mozilla Foundation Security Advisory 2021-49
CVE: CVE-2021-38505
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 91.3
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1730194https://www.mozilla.org/security/advisories/mfsa2021-48/https://www.mozilla.org/security/advisories/mfsa2021-49/https://www.mozilla.org/security/advisories/mfsa2021-50/https://bugzilla.mozilla.org/show_bug.cgi?id=1730194https://www.mozilla.org/security/advisories/mfsa2021-48/https://www.mozilla.org/security/advisories/mfsa2021-49/https://www.mozilla.org/security/advisories/mfsa2021-50/
2021-12-08
Published