CVE-2020-12423: High severity thunderbird vulnerability
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. Note: This issue only affects the Windows operating system; other operating systems are unaffected. This vulnerability affects Firefox < 78.
Other sources
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. Note: This issue only affects the Windows operating system; other operating systems are unaffected.
— Mozilla
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Thunderbird may have loaded the DLL, leading to arbitrary code execution. Note: This issue only affects the Windows operating system; other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-12423?
CVE-2020-12423 is a vulnerability where the Windows DLL webauthn.dll was missing from the operating system and a malicious one was placed in a folder in the user's %PATH%, which could lead to arbitrary code execution in Thunderbird.
Which operating systems are affected by CVE-2020-12423?
This vulnerability only affects the Windows operating system.
What is the severity of CVE-2020-12423?
CVE-2020-12423 has a severity level of medium.
How can I fix CVE-2020-12423?
To fix this vulnerability, update Mozilla Thunderbird to version 78 or later.
Where can I find more information about CVE-2020-12423?
You can find more information about CVE-2020-12423 on the Mozilla website.