CVE-2021-38492: Medium severity firefox esr vulnerability
When delegating navigations to the operating system, Firefox would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
Other sources
When delegating navigations to the operating system, Firefox would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Firefox for Windows. Other operating systems are unaffected.
When delegating navigations to the operating system, Thunderbird would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Thunderbird for Windows. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-38492?
CVE-2021-38492 has been classified as a moderate severity vulnerability affecting Firefox on Windows.
How do I fix CVE-2021-38492?
To fix CVE-2021-38492, update Firefox or Thunderbird to version 91.1 or higher.
Who is affected by CVE-2021-38492?
CVE-2021-38492 affects users of Firefox and Thunderbird on Windows operating systems.
Can CVE-2021-38492 be exploited remotely?
Yes, CVE-2021-38492 can potentially be exploited by attackers to execute scripts on unprivileged pages.
Is CVE-2021-38492 applicable to other operating systems?
No, CVE-2021-38492 is specific to Firefox on Windows and does not affect other operating systems.