Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
|
— |
153.2.0
|
|
Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
|
154.0
|
155.0
|