CVE-2025-3033

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 7, 2025
CWE ID 73

Summary

CVE-2025-3033 is a vulnerability that affects Firefox and Thunderbird on Windows operating systems. By manipulating a malicious Windows `.url` shortcut, an attacker could cause an unexpected file to be uploaded to the affected software. This issue does not impact Firefox or Thunderbird on other operating systems. Firefox versions prior to 137 and Thunderbird versions prior to 137 are vulnerable to this exploit.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share