LiveActive security incident?Get immediate response
CVE Record

CVE-2019-11697: If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will...

If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension. This vulnerability affects Firefox < 67.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2019-11697 is a Firefox UI security flaw. If a user received an extension installation prompt and pressed ALT+a, the normal prompt delay could be bypassed, allowing installation sooner than intended. A malicious page could combine this with spoofing to trick a user into installing a malicious extension. The source bundle says Firefox before 67 is affected.

Executive priority

Treat this as a cleanup and browser governance issue, not an emergency based on the supplied evidence. Prioritize remediation where legacy Firefox remains in production or users can install extensions freely.

Technical view

The issue is in Firefox's extension installation prompt handling. The prompt delay that prevents immediate acceptance could be skipped when ALT and a were pressed. This does not describe remote code execution by itself; the documented risk is malicious extension installation through user deception. Sources identify Firefox versions before 67 as affected.

Likely exposure

Exposure is mainly legacy Firefox installations older than version 67. Organizations with unmanaged browsers, old gold images, kiosks, or unsupported endpoints are more likely to retain exposure.

Exploitation context

The bundle does not show active exploitation and KEV is false. Exploitation requires a user-facing extension install prompt plus social engineering or page spoofing to induce the relevant keyboard action.

Researcher notes

Evidence is limited to the CVE description, Mozilla advisory reference, and Bugzilla reference. The bundle provides no CVSS score, CWE, exploit proof, or workaround details beyond affected Firefox versions before 67.

Mitigation direction

  • Upgrade Firefox to version 67 or later, preferably a currently supported release.
  • Audit managed endpoints for Firefox versions older than 67.
  • Restrict extension installation through enterprise browser policy where appropriate.
  • Review Mozilla guidance for any environment-specific remediation details.

Validation and detection

  • Inventory Firefox versions across workstations, kiosks, and VDI images.
  • Confirm no production endpoint is running Firefox before version 67.
  • Check enterprise policies controlling browser extension installation.
  • Review helpdesk or EDR telemetry for suspicious extension installation reports.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-11697 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MozillaFirefoxunspecifiedListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.