CVE-2020-15657

HIGH

Mozilla Firefox < 79.0 - Uncontrolled Search Path

Title source: rule

Description

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 41.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (3)

mozilla/firefox < 79.0
mozilla/firefox_esr < 78.1
mozilla/thunderbird < 78.1

Timeline

Published Aug 10, 2020
Tracked Since Feb 18, 2026