On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft windows Mozilla Mozilla firefox Mozilla thunderbird |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Microsoft
Microsoft windows Mozilla Mozilla firefox Mozilla thunderbird |

Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-03-13T18:19:17.795Z
Reserved: 2024-06-06T15:05:13.422Z
Link: CVE-2024-5692

Updated: 2024-08-01T21:18:06.916Z

Status : Analyzed
Published: 2024-06-11T13:15:50.770
Modified: 2025-03-27T20:07:17.167
Link: CVE-2024-5692
