Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1843758 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2023-34/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-35/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-36/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-37/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-38/ | vendor advisory |