First published: Tue Feb 14 2023(Updated: )
After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.This bug only affects Firefox for Windows. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <110 | 110 |
<110 | 110 | |
Mozilla Firefox | <110.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-25740 is a vulnerability in Firefox that allows an attacker to supply a remote path in a downloaded .scf script, leading to unexpected network requests and potential leakage of NTLM credentials.
Firefox versions up to but not including 110 are affected by CVE-2023-25740.
CVE-2023-25740 has a severity rating of medium.
To fix CVE-2023-25740, update Firefox to version 110 or higher.
You can find more information about CVE-2023-25740 on the Mozilla website.