CVE-2023-25740
HIGHMozilla Firefox < 110.0 - Insufficiently Protected Credentials
Title source: ruleDescription
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.
Scores
CVSS v3
8.8
EPSS
0.0023
EPSS Percentile
45.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
published
Affected Products (1)
mozilla/firefox
< 110.0
Timeline
Published
Jun 02, 2023
Tracked Since
Feb 18, 2026