CVE-2025-3033
CVSS 3.1 Score 7.7 of 10 (high)
Details
Published Apr 1, 2025
Updated: Apr 7, 2025
CWE ID 73
Summary
CVE-2025-3033 is a vulnerability that affects Firefox and Thunderbird on Windows operating systems. By manipulating a malicious Windows `.url` shortcut, an attacker could cause an unexpected file to be uploaded to the affected software. This issue does not impact Firefox or Thunderbird on other operating systems. Firefox versions prior to 137 and Thunderbird versions prior to 137 are vulnerable to this exploit.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.