CVE-2020-35112

HIGH

Firefox <84, Thunderbird <78.6, Firefox ESR <78.6 - Path Traversal

Title source: llm
STIX 2.1

Description

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

References (4)

Core 4
Core References
Permissions Required x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1661365

Scores

CVSS v3 8.8
EPSS 0.0053
EPSS Percentile 67.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
mozilla/firefox < 84.0
mozilla/firefox_esr < 78.6.0
mozilla/thunderbird < 78.6.0
Published Jan 07, 2021
Tracked Since Feb 18, 2026