Cyber Resilience

CVE-2023-29542

Mozilla Firefox ≤ 112.0

Published
19 June 2023
Modified
11 December 2024
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0094 58th percentile
Risk Priority 73 floored blend · peak EPSS

Summary

CVE-2023-29542 is a critical-severity an unspecified weakness vulnerability in Mozilla Firefox. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 42% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects…

more

Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-4576Same product: Microsoft Windows
CVE-2023-29532Same product: Microsoft Windows
CVE-2023-5727Same product: Microsoft Windows
CVE-2023-5168Same product: Microsoft Windows
CVE-2023-5174Same product: Microsoft Windows
CVE-2023-25734Same product: Microsoft Windows
CVE-2023-25738Same product: Microsoft Windows
CVE-2023-32214Same product: Microsoft Windows
CVE-2024-5692Same product: Microsoft Windows
CVE-2023-4054Same product: Microsoft Windows

Affected Assets

mozilla
firefox
≤ 112.0
mozilla
firefox esr
≤ 102.10
mozilla
thunderbird
≤ 102.10

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References