CVE-2023-25734
published 2023-06-02CVE-2023-25734: After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from…
PriorityP341high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.78%
51.7th percentile
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 110.0 | 110.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 110 | 110 |
| mozilla | firefox_esr | < 102.8 | 102.8 |
| mozilla | firefox_esr | >= unspecified < 102.8 | 102.8 |
| mozilla | thunderbird | < 102.8 | 102.8 |
| mozilla | thunderbird | >= unspecified < 102.8 | 102.8 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vendor_debian8.1LOW
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Opening local .url files could cause unexpected network loads
vendor_redhat·2023-02-14·CVSS 8.1
CVE-2023-25734 [HIGH] CWE-73 Mozilla: Opening local .url files could cause unexpected network loads
Mozilla: Opening local .url files could cause unexpected network loads
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
The Mozilla Foundation Security Advisory describes this flaw as:
After downloading a Windows `.url` shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials t
Debian
CVE-2023-25734: firefox - After downloading a Windows <code>.url</code> shortcut from the local filesystem...
vendor_debian·2023·CVSS 8.1
CVE-2023-25734 [HIGH] CVE-2023-25734: firefox - After downloading a Windows <code>.url</code> shortcut from the local filesystem...
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-05: CVE-2023-25734
vendor_mozilla·CVSS 8.1
CVE-2023-25734 [HIGH] Mozilla Foundation Security Advisory 2023-05: CVE-2023-25734
Mozilla Foundation Security Advisory 2023-05
CVE: CVE-2023-25734
Product: Firefox
Impact: high
Fixed in: Firefox 110
Mozilla
Mozilla Foundation Security Advisory 2023-06: CVE-2023-25734
vendor_mozilla·CVSS 8.1
CVE-2023-25734 [HIGH] Mozilla Foundation Security Advisory 2023-06: CVE-2023-25734
Mozilla Foundation Security Advisory 2023-06
CVE: CVE-2023-25734
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.8
Mozilla
Mozilla Foundation Security Advisory 2023-07: CVE-2023-25734
vendor_mozilla·CVSS 8.1
CVE-2023-25734 [HIGH] Mozilla Foundation Security Advisory 2023-07: CVE-2023-25734
Mozilla Foundation Security Advisory 2023-07
CVE: CVE-2023-25734
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.8
GHSA
GHSA-wpvr-v2cc-f6qx: After downloading a Windows
ghsa_unreviewed·2023-06-02
CVE-2023-25734 [HIGH] CWE-601 GHSA-wpvr-v2cc-f6qx: After downloading a Windows
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1784451https://bugzilla.mozilla.org/show_bug.cgi?id=1809923https://bugzilla.mozilla.org/show_bug.cgi?id=1810143https://bugzilla.mozilla.org/show_bug.cgi?id=1812338https://www.mozilla.org/security/advisories/mfsa2023-05/https://www.mozilla.org/security/advisories/mfsa2023-06/https://www.mozilla.org/security/advisories/mfsa2023-07/https://bugzilla.mozilla.org/show_bug.cgi?id=1784451https://bugzilla.mozilla.org/show_bug.cgi?id=1809923https://bugzilla.mozilla.org/show_bug.cgi?id=1810143https://bugzilla.mozilla.org/show_bug.cgi?id=1812338https://www.mozilla.org/security/advisories/mfsa2023-05/https://www.mozilla.org/security/advisories/mfsa2023-06/https://www.mozilla.org/security/advisories/mfsa2023-07/
2023-06-02
Published