Windows Thunderbird - Firefox Vulnerability

Windows Thunderbird - Firefox Vulnerability

According to the vulnerability report which has been released on 27th of June; a newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download.

Windows Thunderbird - Firefox Vulnerability

This could may lead to accidental execution of malicious code. Only Firefox and Thunderbird on Windows are affected by this bug. Other versions of Firefox and Thunderbird remain unaffected. (CVE-2023-29542)

Affected Systems

This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

Configuration 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*Up to (excluding)112.0
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*Up to (excluding)102.10
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*Up to (excluding) 102.10
Running on/with
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

IoC’s

-

Recommended Solution(s)

-

Mitigations

-

CVE / CWE

CVE-2023-29542

Related Website(s)

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.