vulnerability
MFSA2024-28 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.12 (CVE-2024-5692)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:N/I:C/A:N) | Jun 11, 2024 | Jun 14, 2024 | Jul 28, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:C/A:N)
Published
Jun 11, 2024
Added
Jun 14, 2024
Modified
Jul 28, 2025
Description
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Solution
mozilla-thunderbird-upgrade-115_12
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.