cve/2023/CVE-2023-25740.md

18 lines
931 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-25740](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25740)
![](https://img.shields.io/static/v1?label=Product&message=Firefox&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20110%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Opening%20local%20.scf%20files%20could%20cause%20unexpected%20network%20loads&color=brighgreen)
### Description
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon