CVE-2018-18496: High severity firefox vulnerability
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. Note: This issue only affects Windows operating systems. Other operating systems are not affected.. This vulnerability affects Firefox < 64.
Other sources
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. Note: This issue only affects Windows operating systems. Other operating systems are not affected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18496?
CVE-2018-18496 is a vulnerability in Mozilla Firefox that allows for a clickjacking attack by confusing users into downloading and executing an executable file.
Which operating systems are affected by CVE-2018-18496?
CVE-2018-18496 only affects Windows operating systems.
What is the severity rating of CVE-2018-18496?
CVE-2018-18496 has a severity rating of 8.8 (high).
How can I fix CVE-2018-18496?
Update your Mozilla Firefox browser to version 64 or higher.
Where can I find more information about CVE-2018-18496?
You can find more information about CVE-2018-18496 on the Mozilla Bugzilla and Mozilla Security Advisories websites.