A hyperlink using protocols associated with Internet Explorer, such as `IE.HTTP:`, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.* External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2019-16/#CVE-2019-11702
Acknowledgments: Name: the Mozilla project Upstream: James Lee
Statement: This vulnerability only affects versions of Firefox on the Windows operating system. Red Hat Enterprise Linux is not affected.
Hi Doran, Thank you so much for kindly creating this BZ to confirm it does not affect RHEL Firefox. Thanks Kazu