CVE-2024-5692
Published: Jun 11, 2024
Modified: Feb 27, 2026
Description
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 127 |
Mozilla | Firefox ESR | affected unspecified - < 115.12 |
Mozilla | Thunderbird | affected unspecified - < 115.12 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now