First published: Tue Jun 11 2024(Updated: )
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as .url by including an invalid character in the extension. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <115.12 | 115.12 |
Firefox | <127 | 127 |
Firefox ESR | <115.12 | 115.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-5692 has been classified as a moderate severity vulnerability.
To fix CVE-2024-5692, update to the latest version of Firefox, Firefox ESR, or Thunderbird as specified in the affected software section.
CVE-2024-5692 affects Mozilla Firefox versions prior to 127.
CVE-2024-5692 impacts users of Windows 10 who utilize the 'Save As' functionality in affected Mozilla products.
CVE-2024-5692 is a file extension spoofing vulnerability that can be exploited to save files with disallowed extensions.