CVE-2025-3033
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded.
*
After selecting a malicious Windows .url shortcut from the local filesystem, an unexpected file could be uploaded. This bug only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
HIGH · CVSS 7.7
EPSS 0.00067
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0