CVE-2024-8383

NVD Published Date: September 03, 2024 at 01:15 PM
NVD Last Modified: September 06, 2024 at 07:15 PM
Download Patch
Vulnerability ID
CVE-2024-8383
Severity
HIGH
Severity Score
7.5
Summary
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Mitigation and Patches
-
Exploits
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE ID
NVD-CWE-noinfo

Recent Publish

CVE-2024-6232

2024-01 Cumulative Update for Windows 10 Version 21H2 for x86-based Systems (KB5034122)

2024-01 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5034122)

2024-01 Dynamic Cumulative Update for Windows 10 Version 21H2 for x86-based Systems (KB5034122)

2024-01 Dynamic Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5034122)

2024-01 Dynamic Cumulative Update for Windows 10 Version 21H2 for ARM64-based Systems (KB5034122)

See SecOps Solution
in action

Schedule Demo