CVE-2023-29542: Mozilla Firefox
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Affected products
- Mozilla Firefox: before 112.0 (fixed in 112.0)
- Mozilla Firefox ESR: before 102.10 (fixed in 102.10)
- Mozilla Thunderbird: before 102.10 (fixed in 102.10)
Published 2023-06-19. Last modified 2026-06-17.