CVE-2022-36314Uncontrolled Search Path Element in Mozilla Firefox

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 87.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22

Description

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified103
NVDmozilla/firefox< 103.0
CVEListV5mozilla/firefox_esrunspecified102.1
NVDmozilla/firefox_esr< 102.1
CVEListV5mozilla/thunderbirdunspecified102.1

🔴Vulnerability Details

3
GHSA
GHSA-m6jf-wj3w-42j2: When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from2022-12-22
OSV
CVE-2022-36314: When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from2022-12-22
CVEList
CVE-2022-36314: When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from2022-12-22

📋Vendor Advisories

5
Red Hat
Mozilla: Opening local <code>.lnk</code> files could cause unexpected network loads2022-07-26
Debian
CVE-2022-36314: firefox - When opening a Windows shortcut from the local filesystem, an attacker could sup...2022
Mozilla
Mozilla Foundation Security Advisory 2022-32: CVE-2022-36314
Mozilla
Mozilla Foundation Security Advisory 2022-28: CVE-2022-36314
Mozilla
Mozilla Foundation Security Advisory 2022-30: CVE-2022-36314

💬Community

1
Bugzilla
Download LNK files with a different suffix?2020-08-18
CVE-2022-36314 — Uncontrolled Search Path Element | cvebase