Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34478


The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.<br>*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.


Published

2022-12-22T20:15:32.903

Last Modified

2025-04-15T19:16:03.930

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 102.0 Yes
Application mozilla firefox_esr < 91.11 Yes
Application mozilla thunderbird < 91.11 Yes
Operating System microsoft windows - No

References