First published: Tue Apr 01 2025(Updated: )
After selecting a malicious Windows .url shortcut from the local filesystem, an unexpected file could be uploaded. This bug only affects Firefox on Windows. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <137 | 137 |
Thunderbird | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-3033 has been classified as a moderate severity vulnerability affecting Firefox on Windows.
To mitigate CVE-2025-3033, users should update Firefox or Thunderbird to version 137 or later.
CVE-2025-3033 specifically affects the Firefox and Thunderbird applications on Windows operating systems.
CVE-2025-3033 is a file upload vulnerability that occurs when a malicious Windows .url shortcut is selected.
No, CVE-2025-3033 only affects Windows systems; other operating systems are not at risk from this vulnerability.