CVE-2024-5692: Medium severity Mozilla Thunderbird vulnerability
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as .url by including an invalid character in the extension. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
Other sources
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as .url by including an invalid character in the extension. Note: This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
— NVD
On Windows, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as .url by including an invalid character in the extension. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5692?
CVE-2024-5692 has been classified as a moderate severity vulnerability.
How do I fix CVE-2024-5692?
To fix CVE-2024-5692, update to the latest version of Firefox, Firefox ESR, or Thunderbird as specified in the affected software section.
Which versions of Firefox are affected by CVE-2024-5692?
CVE-2024-5692 affects Mozilla Firefox versions prior to 127.
Who is impacted by CVE-2024-5692?
CVE-2024-5692 impacts users of Windows 10 who utilize the 'Save As' functionality in affected Mozilla products.
What type of vulnerability is CVE-2024-5692?
CVE-2024-5692 is a file extension spoofing vulnerability that can be exploited to save files with disallowed extensions.