CVE-2023-4054Insufficient UI Warning of Dangerous Operations in Mozilla Firefox

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 90.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1

Description

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified116
NVDmozilla/firefox102.0102.14+2
CVEListV5mozilla/firefox_esrunspecified102.14+1
CVEListV5mozilla/thunderbirdunspecified102.14+1
Ubuntumozilla/thunderbird< 1:102.15.0+build1-0ubuntu0.20.04.1+1

🔴Vulnerability Details

3
GHSA
GHSA-ww29-fh6f-953x: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code2023-08-01
CVEList
CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code2023-08-01
OSV
CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code2023-08-01

📋Vendor Advisories

8
Red Hat
Mozilla: Lack of warning when opening appref-ms files2023-08-01
Juniper
CVE-2023-22396: An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated2023-01-13
Debian
CVE-2023-4054: firefox - When opening appref-ms files, Firefox did not warn the user that these files may...2023
Mozilla
Mozilla Foundation Security Advisory 2023-33: CVE-2023-4054
Mozilla
Mozilla Foundation Security Advisory 2023-29: CVE-2023-4054
CVE-2023-4054 — Mozilla Firefox vulnerability | cvebase