CVE-2023-28163
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jun 2, 2023
Updated: Jan 9, 2025
CWE ID 22
Summary
CVE-2023-28163 is a vulnerability affecting Firefox and Thunderbird on Windows. When using the "Save As" dialog to download files with suggested filenames containing environment variable names, Windows incorrectly resolves these names in the context of the current user. This issue, exclusive to Firefox versions below 111, Firefox ESR below 102.9, and Thunderbird below 102.9, may lead to potential security risks due to unintended file saving or execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.