Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
2020-08-10T18:15:12.593
2024-11-21T05:05:57.533
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 79.0 | Yes |
| Application | mozilla | firefox_esr | < 78.1 | Yes |
| Application | mozilla | thunderbird | < 78.1 | Yes |
| Operating System | microsoft | windows | - | No |