CVE-2020-15657

HIGH

Firefox < 79.0 and Firefox ESR < 78.1 - Uncontrolled Search Path Element via DLL Loading

Title source: llm
STIX 2.1

Description

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

References (5)

Core 5
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1644954
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.html

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 41.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (3)
mozilla/firefox < 79.0
mozilla/firefox_esr < 78.1
mozilla/thunderbird < 78.1
Published Aug 10, 2020
Tracked Since Feb 18, 2026