Back

MEDIUM

Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content

Published Apr 26, 2019

Description

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Affected products

Remediation

Red Hat statement

This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 6 and 7.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Apr 26, 2019
Updated Aug 4, 2024
Reserved Mar 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 20, 2019