CVE-2019-11700: Medium severity firefox vulnerability
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. Note: this issue only occurs on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 67.
Other sources
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. Note: this issue only occurs on Windows. Other operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11700?
CVE-2019-11700 is a vulnerability in Firefox < 67 that allows a hyperlink using the res: protocol to open local files on Windows.
How does CVE-2019-11700 work?
CVE-2019-11700 works by tricking a user into clicking on a hyperlink that uses the res: protocol, which then opens a local file on the user's computer.
Is CVE-2019-11700 a critical vulnerability?
No, CVE-2019-11700 is classified as a medium severity vulnerability with a CVSS score of 6.5.
How can I fix CVE-2019-11700?
To fix CVE-2019-11700, update Firefox to version 67 or higher.
Are other operating systems affected by CVE-2019-11700?
No, CVE-2019-11700 only affects Windows operating systems. Other operating systems are not affected.