CVE-2020-35112: High severity thunderbird vulnerability
If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Other sources
If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead.Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-35112?
CVE-2020-35112 is categorized as a high severity vulnerability.
How do I fix CVE-2020-35112?
To fix CVE-2020-35112, update to Mozilla Firefox version 84 and later or Firefox ESR version 78.6 and later.
What is the impact of CVE-2020-35112?
The impact of CVE-2020-35112 is that it could lead to unintended execution of executable files when opening files without extensions.
Which software versions are affected by CVE-2020-35112?
CVE-2020-35112 affects Mozilla Firefox versions prior to 84, Firefox ESR versions prior to 78.6, and Thunderbird versions prior to 78.6.
What platforms are vulnerable to CVE-2020-35112?
CVE-2020-35112 affects users on the Windows operating system.