CVE-2019-9794: Critical severity firefox vulnerability
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. Note: This issue only affects Windows operating systems. Other operating systems are unaffected.
Other sources
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. Note: This issue only affects Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-9794.
What is the severity level of CVE-2019-9794?
The severity level of CVE-2019-9794 is critical.
Which software products are affected by CVE-2019-9794?
The software products affected by CVE-2019-9794 are Mozilla Firefox (version up to exclusive 66), Mozilla Thunderbird (version up to exclusive 60.6), and Mozilla Firefox ESR (version up to exclusive 60.6).
How can CVE-2019-9794 be exploited?
CVE-2019-9794 can be exploited by using specific command line arguments during Firefox invocation as a shell handler for URLs to retrieve and execute files.
Are Microsoft Windows systems vulnerable to CVE-2019-9794?
No, Microsoft Windows systems are not vulnerable to CVE-2019-9794.