CVE-2020-12423

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.14 % (50th)
0.14% Progress
Affected Products 2
Advisories 7

When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. Note: This issue only affects the Windows operating system; other operating systems are unaffected. This vulnerability affects Firefox < 78.

Weaknesses
CWE-427
Uncontrolled Search Path Element
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-07-09 15:15:12
(4 years ago)
Updated Date
2023-01-30 17:21:32
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 78.0 version cpe:2.3:a:mozilla:firefox < 78.0
OR  
  Running on/with
  Microsoft Windows cpe:2.3:o:microsoft:windows:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...