CVE-2024-11697 Information

Description

When handling keypress events an attacker may have been able to trick a user into bypassing the \Open Executable File?\ confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133 Firefox ESR < 128.5 Thunderbird < 133 and Thunderbird < 128.5.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1842187 https://www.mozilla.org/security/advisories/mfsa2024-63/ https://www.mozilla.org/security/advisories/mfsa2024-64/ https://www.mozilla.org/security/advisories/mfsa2024-67/ https://www.mozilla.org/security/advisories/mfsa2024-68/

Share on: