CVE-2020-15657: Mozilla Firefox

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Affected products

  • Mozilla Firefox: before 79.0 (fixed in 79.0)
  • Mozilla Firefox ESR: before 78.1 (fixed in 78.1)
  • Mozilla Thunderbird: before 78.1 (fixed in 78.1)

Published 2020-08-10. Last modified 2026-06-17.