Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2009-68

NTLM reflection vulnerability

Announced
December 15, 2009
Reporter
Takehiro Takahashi
Impact
High
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 3.0.16
  • Firefox 3.5.6
  • SeaMonkey 2.0.1

Description

Security researcher Takehiro Takahashi of the IBM X-Force reported that Mozilla's NTLM implementation was vulnerable to reflection attacks in which NTLM credentials from one application could be forwarded to another arbitary application via the browser. If an attacker could get a user to visit a web page he controlled he could force NTLM authenticated requests to be forwarded to another application on behalf of the user.

References