After downloading a Windows <code>.url</code> shortcut...
High severity
Unreviewed
Published
Jun 2, 2023
to the GitHub Advisory Database
•
Updated Jan 9, 2025
Description
Published by the National Vulnerability Database
Jun 2, 2023
Published to the GitHub Advisory Database
Jun 2, 2023
Last updated
Jan 9, 2025
After downloading a Windows
.url
shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
References