PT-2018-3037 · Mozilla+3 · Firefox Esr+5

·

CVE-2018-12368

·

Publicado

2018-06-26

·

Atualizado

2024-10-21

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 61 Firefox ESR versions prior to 60.1 Firefox ESR versions prior to 52.9 Thunderbird versions prior to 60 Thunderbird versions prior to 52.9
Description The issue is related to security setting errors in Firefox, Firefox ESR, and the Thunderbird email client. It may allow a remote attacker to execute arbitrary code by running a malicious executable file. This problem can be exploited on Windows 10 systems without warning users before opening executable files with the SettingContent-ms extension, even if they have been downloaded from the internet. The vulnerability can also enable a WebExtension with limited downloads.open permission to execute arbitrary code without user interaction on Windows 10 systems.
Recommendations For Firefox versions prior to 61, update to version 61 or later. For Firefox ESR versions prior to 60.1, update to version 60.1 or later. For Firefox ESR versions prior to 52.9, update to version 52.9 or later. For Thunderbird versions prior to 60, update to version 60 or later. For Thunderbird versions prior to 52.9, update to version 52.9 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1952
ALT-PU-2018-1978
ALT-PU-2018-1985
ALT-PU-2018-2669
BDU:2019-03470
CVE-2018-12368
MGASA-2018-0480
SUSE-SU-2018:2298-1
SUSE-SU-2018:2322-1
SUSE-SU-2018:2322-2
SUSE-SU-2018:2325-1

Produtos afetados

Alt Linux
Firefox
Firefox Esr
Suse
Thunderbird
Windows 10