SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-34478

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt.

MEDIUM 6.5EPSS 0.78%

Does this matter?

Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.

Description

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.<br>*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
0.78% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.