CVE-2020-15657: High severity thunderbird vulnerability
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
Other sources
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15657.
What software is affected by this vulnerability?
Mozilla Firefox ESR 78.1, Mozilla Firefox 79, and Mozilla Thunderbird 78.1 are affected by this vulnerability.
What is the severity of CVE-2020-15657?
The severity of CVE-2020-15657 is low.
How can an attacker exploit this vulnerability?
The attacker needs to be capable of placing files in the installation directory to exploit this vulnerability.
Are operating systems other than Windows affected by this vulnerability?
No, this vulnerability only affects Windows operating systems.