Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 79.0 |
| mozilla / firefox_esr | - | 78.1 |
| mozilla / thunderbird | - | 78.1 |