AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-28163

MEDIUM · CVSS 6.5 EPSS 0.80%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-02 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Windows, Firefox.

CVE
CVE-2023-28163
Severity
MEDIUM
CVSS
6.5
EPSS
0.80%
Windows Firefox

Original NVD Description

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. <br>*This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)