Security features bypass in Firefox ESR and Mozilla Firefox - CVE-2024-5692
Published: June 11, 2024
Firefox ESR
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error when parsing file names using the Save As functionality on Windows 10. A remote attacker can trick the victim into saving the file with a disallowed extension such as .url by including an invalid character in the extension.
Note, the vulnerability affects only Windows installations of Firefox.