Back

HIGH

Mozilla: Opening an extension-less download may have inadvertently launched an executable instead

Published Jan 7, 2021

Description

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Jan 7, 2021
Updated Aug 4, 2024
Reserved Dec 10, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Dec 15, 2020
Bugzilla 1908028

ENISA EUVD

Assigner mozilla
Published Jan 7, 2021
Updated Aug 4, 2024

GitHub

No data