CVE-2020-35112 describes a critical vulnerability in Firefox, Thunderbird, and Firefox ESR on Windows, where opening a downloaded file without an extension could inadvertently launch an identically named executable from the same directory. This high-severity flaw (CVSS 8.8) allows for remote code execution with user interaction, as an attacker could trick a user into downloading a benign-looking file to execute malicious code. While the vulnerability has a high risk score, there is no evidence of active exploitation, nor are there public exploit codes or Metasploit modules available. Community discussion and media coverage are minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 78.6.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 78.6.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.