CVE-2025-2817

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
29/04/2025
Last modified:
03/11/2025

Description

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 115.23.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* 138.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 116.0 (including) 128.10.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 128.10.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 129.0 (including) 138.0 (excluding)