Security vulnerabilities fixed in Firefox 67.0.2

Related Vulnerabilities: CVE-2019-11702  

Mozilla Foundation Security Advisory 2019-16

Security vulnerabilities fixed in Firefox 67.0.2

Announced
June 11, 2019
Impact
moderate
Products
Firefox
Fixed in
  • Firefox 67.0.2

#CVE-2019-11702: IE protocols can be used to open known local files

Reporter
James Lee
Impact
moderate
Description

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted.
Note: this issue only occurs on Windows. Other operating systems are unaffected.

References