KEVIntel
6.5
CVSS
Medium

CVE-2022-34478

PUBLISHED

The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These...

Exploited in the wild Remote Low complexity
Vendor
Mozilla
Product
Firefox, Firefox ESR, Thunderbird
Published
Dec 22, 2022
EPSS

Description

The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

windows

CVSS scores

CVSS v3.1 6.5 Medium

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Exploitation status

Exploited in the wild

Recorded 2022-12-22 00:00:00 UTC · Source

SSVC decision points

Exploitation
none
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE Dec 22, 2022

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel