MS.IE.FirefoxURL.Protocol.Handler.Command.Injection

description-logoDescription

An argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross browser scripting attacks and execute arbitrary commands. This can be accomplished via shell metacharacters in a FirefoxURL or FirefoxHTML URI, which is inserted into the command line that is created when invoking firefox.exe.

affected-products-logoAffected Products

Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 7.0 beta3
Microsoft Internet Explorer 7.0 beta2
Microsoft Internet Explorer 7.0 beta1
Microsoft Internet Explorer 7.0

Impact logoImpact

System compromise.

recomended-action-logoRecommended Actions

Do not browse untrusted sites.
Disable the "Firefox URL" URI handler.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)