CVE-2025-3033

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded.  
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
mozillaCNA
---
---
CISA-ADPADP
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
mozillafirefox
𝑥
< 137.0
mozillathunderbird
𝑥
< 137.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
140.0.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
plucky
not-affected
oracular
not-affected
noble
not-affected
jammy
not-affected
focal
dne
thunderbird
plucky
not-affected
oracular
not-affected
noble
not-affected
jammy
not-affected
focal
dne