CVE-2023-25740: High severity firefox vulnerability
After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Other sources
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 110.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25740?
CVE-2023-25740 is a vulnerability in Firefox that allows an attacker to supply a remote path in a downloaded .scf script, leading to unexpected network requests and potential leakage of NTLM credentials.
Which software is affected by CVE-2023-25740?
Firefox versions up to but not including 110 are affected by CVE-2023-25740.
What is the severity of CVE-2023-25740?
CVE-2023-25740 has a severity rating of medium.
How can I fix CVE-2023-25740?
To fix CVE-2023-25740, update Firefox to version 110 or higher.
Where can I find more information about CVE-2023-25740?
You can find more information about CVE-2023-25740 on the Mozilla website.