CVE-2020-35112

low
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
2.5

Description

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-35112

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-35112.html

OS impact

OSVersionStatusFixed in
arch archfixed84.0-1
suse slesaffected
debian debiansidfixed0
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiantrixiefixed0

References

Verify integrity in audit chain (admin only). AS-IS.