Mozilla Foundation Security Advisory 2019-16
Security vulnerabilities fixed in Firefox 67.0.2
- Announced
- June 11, 2019
- Impact
- moderate
- Products
- Firefox
- Fixed in
-
- Firefox 67.0.2
#CVE-2019-11702: IE protocols can be used to open known local files
- Reporter
- James Lee
- Impact
- moderate
Description
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:
, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted.
Note: this issue only occurs on Windows. Other operating systems are unaffected.