Lucene search

K
kasperskyKaspersky LabKLA20174
HistoryJan 18, 2023 - 12:00 a.m.

KLA20174 Multiple vulnerabilities in Mozilla Thunderbird

2023-01-1800:00:00
Kaspersky Lab
threats.kaspersky.com
17
mozilla thunderbird
vulnerabilities
security bypass
code execution
ui spoofing
ace
osi
sb
sui
libusrsctp
gtk
devtools
cross-origin iframe
webworker
fullscreen notification
format directive
memory safety
cve-2022-46877
cve-2022-46871
cve-2023-23602
cve-2023-23598
cve-2023-23599
cve-2023-23605
cve-2023-23603
cve-2023-23601
update
affected products

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.2%

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Security bypass vulnerability in libusrsctp can be exploited to bypass security restrictions.
  2. Code execution vulnerability in GTK drag and drop can be exploited remotely to execute arbitrary code.
  3. Code execution vulnerability in Devtools can be exploited remotely to execute arbitrary code.
  4. Security UI vulnerability in cross-origin iframe can be exploited to spoof user interface.
  5. Security vulnerability in WebWorker can be exploited to bypass security restrictions.
  6. Security UI vulnerability in Fullscreen notification can be exploited to spoof user interface.
  7. Security vulnerability in format directive can be exploited to bypass security restrictions.
  8. Memory safety vulnerability can be exploited to execute arbitrary code.

Original advisories

MFSA2023-03

Related products

Mozilla-Thunderbird

CVE list

CVE-2022-46877 warning

CVE-2022-46871 critical

CVE-2023-23602 high

CVE-2023-23598 high

CVE-2023-23599 high

CVE-2023-23605 critical

CVE-2023-23603 high

CVE-2023-23601 high

Solution

Update to the latest version

Download Thunderbird

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Mozilla Thunderbird earlier than 102.7

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.2%