CVE-2024-5692

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

27 Mar 2025, 20:07

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Mozilla thunderbird
Microsoft windows
Mozilla firefox
Mozilla
Microsoft
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1891234 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1891234 - Issue Tracking, Exploit
References () https://www.mozilla.org/security/advisories/mfsa2024-25/ - () https://www.mozilla.org/security/advisories/mfsa2024-25/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-26/ - () https://www.mozilla.org/security/advisories/mfsa2024-26/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-28/ - () https://www.mozilla.org/security/advisories/mfsa2024-28/ - Vendor Advisory

21 Nov 2024, 09:48

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1891234 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1891234 -
References () https://www.mozilla.org/security/advisories/mfsa2024-25/ - () https://www.mozilla.org/security/advisories/mfsa2024-25/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-26/ - () https://www.mozilla.org/security/advisories/mfsa2024-26/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-28/ - () https://www.mozilla.org/security/advisories/mfsa2024-28/ -

01 Aug 2024, 13:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Jun 2024, 23:15

Type Values Removed Values Added
Summary
  • (es) En Windows, al utilizar la función "Guardar como", un atacante podría haber engañado al navegador para que guardara el archivo con una extensión no permitida como ".url" al incluir un carácter no válido en la extensión. *Nota:* Este problema solo afectaba a los sistemas operativos Windows. Otros sistemas operativos no se ven afectados. Esta vulnerabilidad afecta a Firefox &lt; 127 y Firefox ESR &lt; 115.12.
Summary (en) On Windows, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12. (en) On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
References
  • {'url': 'https://bugzilla.mozilla.org/show_bug.cgi?id=1837514', 'source': 'security@mozilla.org'}
  • () https://www.mozilla.org/security/advisories/mfsa2024-28/ -

11 Jun 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-11 13:15

Updated : 2025-03-27 20:07


NVD link : CVE-2024-5692

Mitre link : CVE-2024-5692

CVE.ORG link : CVE-2024-5692


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird

microsoft

  • windows