CVE-2025-3033
EUVD-2025-930201.04.2025, 13:15
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mozilla | firefox | 𝑥 < 137.0 | CNA |
| mozilla | thunderbird | 𝑥 < 137.0 | CNA |
Ubuntu Releases
Common Weakness Enumeration