CVE-2022-34478
The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 24, 2022
- Published Date
- December 22, 2022
- Last Updated
- April 15, 2025
- Vendor
- Mozilla
- Product
- Firefox, Firefox ESR, Thunderbird
- Description
- The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
- Tags
- Exploitation
- none
- Technical Impact
- partial
- Exploited in the Wild
- Yes (2022-12-22 00:00:00 UTC) Source
windows
CVSS Scores
CVSS v3.1
6.5 - MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2022-12-22 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel