828
VMScore

CVE-2018-12368

Published: 18/10/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open permission to execute arbitrary code without user interaction on Windows 10 systems. *Note: this issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox

mozilla firefox_esr

Vendor Advisories

Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web" Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable This also allows a WebExtension with the limited downlo ...
Mozilla Foundation Security Advisory 2018-16 Security vulnerabilities fixed in Firefox ESR 601 Announced June 26, 2018 Impact critical Products Firefox ESR Fixed in Firefox ESR 601 ...
Mozilla Foundation Security Advisory 2018-17 Security vulnerabilities fixed in Firefox ESR 529 Announced June 26, 2018 Impact critical Products Firefox ESR Fixed in Firefox ESR 529 ...
Mozilla Foundation Security Advisory 2018-19 Security vulnerabilities fixed in Thunderbird 60 Announced August 16, 2018 Impact critical Products Thunderbird Fixed in Thunderbird 60 ...
Mozilla Foundation Security Advisory 2018-18 Security vulnerabilities fixed in Thunderbird 529 Announced July 3, 2018 Impact critical Products Thunderbird Fixed in Thunderbird 529 ...
Mozilla Foundation Security Advisory 2018-15 Security vulnerabilities fixed in Firefox 61 Announced June 26, 2018 Impact critical Products Firefox Fixed in Firefox 61 ...

Recent Articles

Thunderbird gets its EFAIL patch
The Register • Richard Chirgwin • 05 Jul 2018

Version 52.9 now does PGP and S/MIME right, adds another dozen bug-splats

Thunderbird has pushed code with fixes for a dozen security vulnerabilities – including the EFAIL encryption mess that emerged in May. The EFAIL-specific fixes address two errors in Thunderbird's handling of encrypted messages: CVE-2018-12372, in which an attacker can build S/MIME and PGP decryption oracles in HTML messages; and CVE-2018-12373, in which S/MIME plaintext can be leaked if a message is forwarded. EFAIL was announced with a much-criticised process. The discoverers emphasised the i...