CVE-2020-12423 is a DLL hijacking vulnerability affecting Mozilla Firefox on Windows operating systems. It allowed arbitrary code execution if a malicious webauthn.dll was placed in a user's %PATH% when the legitimate DLL was missing. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), this vulnerability requires local access and user interaction for exploitation, leading to high confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 78.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 78CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.