CVE-2019-9801: Input Validation
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. Note: This issue only affects Windows operating systems. Other operating systems are unaffected.
Other sources
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. Note: This issue only affects Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-9801?
CVE-2019-9801 is a vulnerability in Firefox and Thunderbird that allows any registered Program ID to be accepted as an external protocol handler on Windows operating systems.
How does CVE-2019-9801 affect Mozilla Firefox?
Mozilla Firefox versions up to and including 66 are affected by CVE-2019-9801.
How does CVE-2019-9801 affect Mozilla Thunderbird?
Mozilla Thunderbird versions up to and including 60.6 are affected by CVE-2019-9801.
What is the severity of CVE-2019-9801?
CVE-2019-9801 has a severity rating of 5.3 (Medium).
How can I mitigate the vulnerability?
Update Mozilla Firefox to version 66 or later, or update Mozilla Thunderbird to version 60.6 or later to mitigate CVE-2019-9801.