CVE-2023-29541
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jun 2, 2023
Updated: Jan 10, 2025
CWE ID 116
Summary
CVE-2023-29541 is a vulnerability affecting Firefox for Linux on select distributions. The browser fails to adequately manage downloads of files with a .desktop extension, potentially enabling attackers to execute unintended commands. This flaw is present in Firefox versions below 112, Focus for Android below 112, Firefox ESR below 102.10, Firefox for Android below 112, and Thunderbird below 102.10. Mozilla has yet to identify all impacted Linux distributions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.