Closed Bug 1921458 (CVE-2024-11693) Opened 1 year ago Closed 1 year ago

Microsoft .library-ms files potentially unsafe

Categories

(Firefox :: File Handling, defect, P2)

Desktop
Windows
defect

Tracking

()

VERIFIED FIXED
134 Branch
Tracking Status
firefox-esr115 --- wontfix
firefox-esr128 133+ verified
firefox132 --- wontfix
firefox133 + verified
firefox134 + verified

People

(Reporter: mak, Assigned: mak)

References

()

Details

(Keywords: csectype-disclosure, sec-moderate, Whiteboard: [adv-main133+][adv-esr128.5+])

Attachments

(4 files)

Chromium has added full ping for .library-ms, the code comment reads as:

  # Windows Library Description Schema. This is a shell extension that can
  # cause information to be leaked to remote file shares.
  # https://learn.microsoft.com/en-us/windows/win32/shell/library-schema-entry

The MS documentation doesn't say much, I found a little bit additional information here
https://wikileaks.org/ciav7p1/cms/page_13763381.html
https://medium.com/@mhwee/unmasking-windows-library-files-a-deep-dive-into-client-side-exploitation-6bf3371a5262

I'm not sure whether we should just add these to the safebrowsing list, or also executable lists.
Doesn't look like a format that has a lot of value when downloaded from the Web, so making it a bit more annoying to execute may not be a big deal.

Summary: Miacrosoft .library-ms files potentially unsafe → Microsoft .library-ms files potentially unsafe

let's add this as executable, considered it's not very commonly downloaded anyway, so adding a warning won't break common workflows.

Assignee: nobody → mak
Status: NEW → ASSIGNED

The severity field is not set for this bug.
:Gijs, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(gijskruitbosch+bugs)
Severity: -- → S3
Flags: needinfo?(gijskruitbosch+bugs)
OS: Unspecified → Windows
Priority: -- → P2
Hardware: Unspecified → Desktop
Attached file Bug 1921458. r=dimi
Group: firefox-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 134 Branch
Attachment #9433992 - Flags: approval-mozilla-beta?

beta Uplift Approval Request

  • User impact if declined: sec-moderate
  • Code covered by automated testing: yes
  • Fix verified in Nightly: no
  • Needs manual QE test: yes
  • Steps to reproduce for manual QE testing: Try downloading a file with one of these extensions. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately execute
  • Risk associated with taking this patch: low
  • Explanation of risk level: Adding file extension to a list
  • String changes made/needed: none
  • Is Android affected?: no
Flags: qe-verify+
Attachment #9433994 - Flags: approval-mozilla-esr128?

esr128 Uplift Approval Request

  • User impact if declined: sec-moderate
  • Code covered by automated testing: yes
  • Fix verified in Nightly: no
  • Needs manual QE test: yes
  • Steps to reproduce for manual QE testing: Try downloading a file with one of these extensions. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately execute
  • Risk associated with taking this patch: Low
  • Explanation of risk level: Adding file extension to a list
  • String changes made/needed: none
  • Is Android affected?: no
Attachment #9433992 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
QA Whiteboard: [post-critsmash-triage]
QA Whiteboard: [post-critsmash-triage] → [post-critsmash-triage] [qa-triaged]

Hi,

I am trying to verify the fix but unfortunately I couldn't find a .library-ms file to download and when I created a new one and renamed it in a local file explorer and then dragged it to the tab-strip it opened the file inside without any prompt (on the fixed versions) could you please attach a file with that extension that I could use?

Thank you!

Flags: needinfo?(mak)
Attachment #9433994 - Flags: approval-mozilla-esr128? → approval-mozilla-esr128+

(In reply to Peter Magyari (Desktop QA) from comment #11)

could you please attach a file with that extension that I could use?

I think you can test using this link https://mime.ty.ax/dl/test.library-ms?ty=txt&ct=application%2Foctet-stream&cd=attachment

Flags: needinfo?(mak)

I have verified the fix on Nightly 134.0a1 (20241104213308), Beta 133.0b4 (20241104091514) and 128.5.0esr (20241102140110).
Thank you for the link Marco!

Status: RESOLVED → VERIFIED
Flags: qe-verify+
Whiteboard: [adv-main133+]
Attached file advisory.txt
Whiteboard: [adv-main133+] → [adv-main133+][adv-esr128.5+]
Alias: CVE-2024-11693
Group: core-security-release
See Also: → CVE-2026-6763
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: