CVE-2022-34478
Last modified
CVE-2022-34478 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.<br>*This bug only affects Thunderbird on Windows. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.<br>*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 102.0 |
| Mozilla | Firefox Esr | < 91.11 |
| Mozilla | Thunderbird | < 91.11 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1773717Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-24/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-25/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-26/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1773717Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-24/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-25/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2022-26/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34478?
How severe is CVE-2022-34478?
How do I fix CVE-2022-34478?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34472If there was a PAC URL set and the server that hosts the PAC…4.3
- CVE-2022-34473The HTML Sanitizer should have sanitized the <code>href</cod…6.1
- CVE-2022-34474Even when an iframe was sandboxed with <code>allow-top-navig…6.1
- CVE-2022-34475SVG <code><use></code> tags that referenced a same-ori…6.1
- CVE-2022-34476ASN.1 parsing of an indefinite SEQUENCE inside an indefinite…9.8
- CVE-2022-34477The MediaError message property should be consistent to avoi…7.5
- CVE-2022-34479A malicious website that could create a popup could have res…6.5
- CVE-2022-3448Use after free in Permissions API in Google Chrome prior to …8.8
- CVE-2022-34480Within the <code>lg_init()</code> function, if several alloc…8.8
- CVE-2022-34481In the <code>nsTArray_Impl::ReplaceElementsAt()</code> funct…8.8
- CVE-2022-34482An attacker who could have convinced a user to drag and drop…8.8
- CVE-2022-34483An attacker who could have convinced a user to drag and drop…8.8
Are you affected by CVE-2022-34478?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
