Back

MEDIUM

Mozilla: Bypass of file name restrictions during saving

Published Jun 11, 2024

Description

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 11, 2024
Updated Feb 27, 2026
Reserved Jun 6, 2024
CISA Vulnrichment
Updated Jan 9, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 11, 2024
ENISA EUVD
Assigner mozilla
Published Jun 11, 2024
Updated Feb 27, 2026
Exploited since n/a
EUVD-2024-46864