CVE-2023-25734
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Jun 2, 2023
Updated: Jan 9, 2025
CWE ID 601
Summary
CVE-2023-25734 is a vulnerability affecting Firefox and Thunderbird on Windows operating systems. After downloading a .url shortcut from the local filesystem, an attacker can supply a remote path, leading to unexpected network requests from the operating system, potentially leaking NTLM credentials to the resource. This issue only impacts Firefox versions below 110, Thunderbird versions below 102.8, and Firefox ESR versions below 102.8.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.