⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-34478Open Redirect in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 64.63%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 22

Description

The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, F

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5mozilla/thunderbirdunspecified102+1
NVDmozilla/thunderbird< 91.11
CVEListV5mozilla/firefoxunspecified102
NVDmozilla/firefox< 102.0
CVEListV5mozilla/firefox_esrunspecified91.11

🔴Vulnerability Details

3
GHSA
GHSA-g6c6-9mmh-32cw: The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt2022-12-22
CVEList
CVE-2022-34478: The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt2022-12-22
VulnCheck
Thunderbird for Windows ms-msdt, search, and search-ms Protocols Vulnerability2022

📋Vendor Advisories

5
Red Hat
Mozilla: Microsoft protocols can be attacked if a user accepts a prompt2022-06-28
Debian
CVE-2022-34478: firefox - The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protoc...2022
Mozilla
Mozilla Foundation Security Advisory 2022-25: CVE-2022-34478
Mozilla
Mozilla Foundation Security Advisory 2022-26: CVE-2022-34478
Mozilla
Mozilla Foundation Security Advisory 2022-24: CVE-2022-34478
CVE-2022-34478 — Open Redirect in Mozilla Firefox | cvebase