CVE-2023-25738

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 9, 2025
CWE ID 125

Summary

CVE-2023-25738 is a newly disclosed vulnerability affecting Firefox browsers on Windows. The issue lies within the printer device driver, which fails to validate certain members of the DEVMODEW struct. Unchecked inputs to these members can result in invalid values, leading to out-of-bounds access to related variables within the browser. This vulnerability poses a risk to Firefox versions under 110, Thunderbird versions under 102.8, and Firefox ESR versions under 102.8. Windows users running these affected applications should update them promptly to mitigate this security concern.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share