cve/2024/CVE-2024-5692.md
2025-09-29 16:08:36 +00:00

1.2 KiB

CVE-2024-5692

Description

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as .url by including an invalid character in the extension. Note: This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

POC

Reference

Github

No PoCs found on GitHub currently.