Security readout for executives and security teams
Plain-English summary
This flaw could let a malicious web page abuse an old Mozilla browser origin-handling bug to run script as if it belonged to another site. The main business risk is legacy Firefox, Firefox ESR, or Thunderbird installations that missed 2017 security updates.
Executive priority
Treat this as a legacy exposure cleanup item unless affected clients are still operational. It is not KEV-listed in the provided data, but browser-origin XSS bugs can create meaningful risk on unpatched endpoints.
Technical view
CVE-2017-5466 involves a page loaded by hyperlink that redirects to a data:text/html URL. On reload, Mozilla assigned the data page the wrong origin, enabling cross-site scripting. The source bundle lists Thunderbird before 52.1, Firefox ESR before 52.1, and Firefox before 53 as affected.
Likely exposure
Exposure is most likely on unmanaged, legacy, offline, kiosk, or embedded systems still running affected Mozilla versions or old vendor packages. Current supported browser and mail-client builds are unlikely to be exposed if properly updated.
Exploitation context
The provided sources do not show known active exploitation, and the CVE is not marked KEV. Exploitation would require user interaction with attacker-controlled content and an affected Mozilla client handling the redirect and reload behavior.
Researcher notes
Focus analysis on version and package evidence. The key technical condition is incorrect origin assignment after a data:text/html redirect and reload. The source bundle does not provide CVSS, CWE, proof-of-concept status, or exploit telemetry.
Mitigation direction
- Upgrade Firefox to 53 or later where still present.
- Upgrade Firefox ESR and Thunderbird to 52.1 or later.
- Apply relevant Linux vendor security updates for Mozilla packages.
- Retire unsupported legacy browser and mail-client builds.
- Check Mozilla and OS vendor advisories for platform-specific guidance.
Validation and detection
- Inventory Firefox, Firefox ESR, and Thunderbird versions across endpoints.
- Confirm installed versions are outside the affected ranges.
- Review package status against RHSA-2017:1106 and RHSA-2017:1201 where applicable.
- Check endpoint management data for unsupported Mozilla applications.
- Prioritize legacy systems that browse external web content or open HTML mail.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-5466 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- RHSA-2017:1106CVE reference · vendor-advisory, x_refsource_REDHAT
- https://www.mozilla.org/security/advisories/mfsa2017-12/CVE reference · x_refsource_CONFIRM
- https://bugzilla.mozilla.org/show_bug.cgi?id=1353975CVE reference · x_refsource_CONFIRM
- https://www.mozilla.org/security/advisories/mfsa2017-10/CVE reference · x_refsource_CONFIRM
- https://www.mozilla.org/security/advisories/mfsa2017-13/CVE reference · x_refsource_CONFIRM
- RHSA-2017:1201CVE reference · vendor-advisory, x_refsource_REDHAT
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
