vendor:
Safari
by:
7.5
CVSS
HIGH
Protocol Handler Command-Injection
77
CWE
Product Name: Safari
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:apple:safari
Platforms Tested: Windows
Apple Safari for Windows Protocol Handler Command-Injection Vulnerability
The vulnerability allows remote attackers to pass arbitrary command-line arguments to any application that can be called through a protocol handler. This vulnerability relies on the use of IFRAME elements and can be combined with Mozilla XPCOM components to cause further damage. Exploiting the vulnerability would allow a remote attacker to influence command options and compromise affected systems in the context of the vulnerable user.
Mitigation:
Apple has released Safari for Windows Beta 3.0.1 to address this vulnerability. Users are advised to update to the latest version.