CVE-2023-4054: Medium severity thunderbird vulnerability
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. This bug only affects Firefox on Windows. Other operating systems are unaffected. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Other sources
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. This bug only affects Firefox on Windows. Other operating systems are unaffected. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. This bug only affects Firefox on Windows. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4054?
CVE-2023-4054 is a vulnerability in Firefox on Windows that allows appref-ms files to execute malicious code without warning.
Which operating systems are affected by CVE-2023-4054?
CVE-2023-4054 only affects Firefox on Windows. Other operating systems are unaffected.
What versions of Firefox are affected by CVE-2023-4054?
Firefox versions less than 116 and Firefox ESR versions less than 102.14 are affected by CVE-2023-4054.
What versions of Thunderbird are affected by CVE-2023-4054?
Thunderbird versions less than 102.14 are affected by CVE-2023-4054.
How can I fix CVE-2023-4054?
To fix CVE-2023-4054, update Firefox to version 116 or later, Firefox ESR to version 102.14 or later, or Thunderbird to version 102.14 or later.