CVE-2023-25734: High severity thunderbird vulnerability
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.This bug only affects Firefox on Windows. Other operating systems are unaffected.
Other sources
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.This bug only affects Thunderbird on Windows. Other operating systems are unaffected.
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25734?
CVE-2023-25734 is a vulnerability that allows an attacker to supply a remote path in a Windows .url shortcut, leading to unexpected network requests from the operating system and potentially leaking NTLM credentials.
Which software is affected by CVE-2023-25734?
CVE-2023-25734 affects Mozilla Thunderbird (up to version 102.8), Mozilla Firefox (up to version 110), and Mozilla Firefox ESR (up to version 102.8).
What is the severity of CVE-2023-25734?
CVE-2023-25734 has a severity rating of medium with a value of 4.
How can an attacker exploit CVE-2023-25734?
An attacker can exploit CVE-2023-25734 by supplying a remote path in a Windows .url shortcut, causing unexpected network requests and potentially leaking NTLM credentials.
How can I mitigate CVE-2023-25734?
To mitigate CVE-2023-25734, update Mozilla Thunderbird, Mozilla Firefox, or Mozilla Firefox ESR to the latest version available, which includes the necessary security fixes.