firefox: thunderbird: Privilege escalation in Firefox Updater

cve CVE-2025-2817 2 sources, 2 claims · Watch

Red Hat writes:
firefox: thunderbird: Privilege escalation in Firefox Updater the claim

What it is to other things

affectsmozilla/firefox
NVD
affectsmozilla/thunderbird
NVD
made_bymozilla
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD8.8
receipt
Source
NVD
Its words
8.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.23",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
                "versionEndExcluding": "115.23.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
                "versionEndExcluding": "138.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
                "versionEndExcluding": "128.10.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
                "versionEndExcluding": "128.10.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
                "versionEndExcluding": "138.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
      },
      {
        "lang": "es",
        "value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
      }
    ],
    "id": "CVE-2025-2817",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-2817",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T03:56:27.621494Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T14:15:32.220",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat8.5
receipt
Source
Red Hat
Its words
8.5
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-2817",
  "CWE": "CWE-94",
  "advisories": [
    "RHSA-2025:7690",
    "RHSA-2025:7691",
    "RHSA-2025:7692",
    "RHSA-2025:7693",
    "RHSA-2025:7694",
    "RHSA-2025:7695",
    "RHSA-2025:7543",
    "RHSA-2025:4756",
    "RHSA-2025:4458",
    "RHSA-2025:7544",
    "RHSA-2025:7545",
    "RHSA-2025:4797",
    "RHSA-2025:7689",
    "RHSA-2025:4753",
    "RHSA-2025:7547",
    "RHSA-2025:4752",
    "RHSA-2025:4751",
    "RHSA-2025:4443",
    "RHSA-2025:7428",
    "RHSA-2025:7506",
    "RHSA-2025:7507",
    "RHSA-2025:4460"
  ],
  "affected_packages": [
    "firefox-0:128.10.0-1.el9_2",
    "thunderbird-0:128.10.0-1.el9_4",
    "firefox-0:128.10.0-1.el8_4",
    "thunderbird-0:128.10.0-1.el8_6",
    "thunderbird-0:128.10.0-1.el9_5",
    "thunderbird-0:128.10.0-1.el10_0",
    "thunderbird-0:128.10.0-1.el9_2",
    "firefox-0:128.10.0-1.el9_4",
    "thunderbird-0:128.10.0-1.el8_4",
    "firefox-0:128.10.0-1.el8_6",
    "firefox-0:128.10.0-1.el9_5",
    "firefox-0:128.10.0-1.el9_6",
    "thunderbird-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el7_9",
    "thunderbird-0:128.10.0-1.el8_2",
    "firefox-0:128.10.0-1.el8_8",
    "firefox-0:128.10.0-1.el8_10",
    "thunderbird-0:128.10.0-1.el8_10",
    "firefox-0:128.10.0-1.el10_0",
    "firefox-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el8_2",
    "thunderbird-0:128.10.0-1.el8_8"
  ],
  "bugzilla": "2362902",
  "bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
  "cvss3_score": "8.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T13:13:33Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
  "severity": "important"
}
—
Cwe
cwe
Red HatCWE-94
receipt
Source
Red Hat
Its words
CWE-94
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-2817",
  "CWE": "CWE-94",
  "advisories": [
    "RHSA-2025:7690",
    "RHSA-2025:7691",
    "RHSA-2025:7692",
    "RHSA-2025:7693",
    "RHSA-2025:7694",
    "RHSA-2025:7695",
    "RHSA-2025:7543",
    "RHSA-2025:4756",
    "RHSA-2025:4458",
    "RHSA-2025:7544",
    "RHSA-2025:7545",
    "RHSA-2025:4797",
    "RHSA-2025:7689",
    "RHSA-2025:4753",
    "RHSA-2025:7547",
    "RHSA-2025:4752",
    "RHSA-2025:4751",
    "RHSA-2025:4443",
    "RHSA-2025:7428",
    "RHSA-2025:7506",
    "RHSA-2025:7507",
    "RHSA-2025:4460"
  ],
  "affected_packages": [
    "firefox-0:128.10.0-1.el9_2",
    "thunderbird-0:128.10.0-1.el9_4",
    "firefox-0:128.10.0-1.el8_4",
    "thunderbird-0:128.10.0-1.el8_6",
    "thunderbird-0:128.10.0-1.el9_5",
    "thunderbird-0:128.10.0-1.el10_0",
    "thunderbird-0:128.10.0-1.el9_2",
    "firefox-0:128.10.0-1.el9_4",
    "thunderbird-0:128.10.0-1.el8_4",
    "firefox-0:128.10.0-1.el8_6",
    "firefox-0:128.10.0-1.el9_5",
    "firefox-0:128.10.0-1.el9_6",
    "thunderbird-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el7_9",
    "thunderbird-0:128.10.0-1.el8_2",
    "firefox-0:128.10.0-1.el8_8",
    "firefox-0:128.10.0-1.el8_10",
    "thunderbird-0:128.10.0-1.el8_10",
    "firefox-0:128.10.0-1.el10_0",
    "firefox-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el8_2",
    "thunderbird-0:128.10.0-1.el8_8"
  ],
  "bugzilla": "2362902",
  "bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
  "cvss3_score": "8.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T13:13:33Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
  "severity": "important"
}
—
Packages
packages
Red Hatfirefox-0:128.10.0-1.el9_2, thunderbird-0:128.10.0-1.el9_4, firefox-0:128.10.0-1.el8_4, thunderbird-0:128.10.0-1.el8_6, thunderbird-0:128.10.0-1.el9_5, thunderbird-0:128.10.0-1.el10_0, thunderbird-0:128.10.0-1.el9_2, firefox-0:128.10.0-1.el9_4, thunderbird-0:128.10.0-1.el8_4, firefox-0:128.10.0-1.el8_6, firefox-0:128.10.0-1.el9_5, firefox-0:128.10.0-1.el9_6, thunderbird-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el7_9, thunderbird-0:128.10.0-1.el8_2, firefox-0:128.10.0-1.el8_8, firefox-0:128.10.0-1.el8_10, thunderbird-0:128.10.0-1.el8_10, firefox-0:128.10.0-1.el10_0, firefox-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el8_2, thunderbird-0:128.10.0-1.el8_8
receipt
Source
Red Hat
Its words
firefox-0:128.10.0-1.el9_2, thunderbird-0:128.10.0-1.el9_4, firefox-0:128.10.0-1.el8_4, thunderbird-0:128.10.0-1.el8_6, thunderbird-0:128.10.0-1.el9_5, thunderbird-0:128.10.0-1.el10_0, thunderbird-0:128.10.0-1.el9_2, firefox-0:128.10.0-1.el9_4, thunderbird-0:128.10.0-1.el8_4, firefox-0:128.10.0-1.el8_6, firefox-0:128.10.0-1.el9_5, firefox-0:128.10.0-1.el9_6, thunderbird-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el7_9, thunderbird-0:128.10.0-1.el8_2, firefox-0:128.10.0-1.el8_8, firefox-0:128.10.0-1.el8_10, thunderbird-0:128.10.0-1.el8_10, firefox-0:128.10.0-1.el10_0, firefox-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el8_2, thunderbird-0:128.10.0-1.el8_8
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-2817",
  "CWE": "CWE-94",
  "advisories": [
    "RHSA-2025:7690",
    "RHSA-2025:7691",
    "RHSA-2025:7692",
    "RHSA-2025:7693",
    "RHSA-2025:7694",
    "RHSA-2025:7695",
    "RHSA-2025:7543",
    "RHSA-2025:4756",
    "RHSA-2025:4458",
    "RHSA-2025:7544",
    "RHSA-2025:7545",
    "RHSA-2025:4797",
    "RHSA-2025:7689",
    "RHSA-2025:4753",
    "RHSA-2025:7547",
    "RHSA-2025:4752",
    "RHSA-2025:4751",
    "RHSA-2025:4443",
    "RHSA-2025:7428",
    "RHSA-2025:7506",
    "RHSA-2025:7507",
    "RHSA-2025:4460"
  ],
  "affected_packages": [
    "firefox-0:128.10.0-1.el9_2",
    "thunderbird-0:128.10.0-1.el9_4",
    "firefox-0:128.10.0-1.el8_4",
    "thunderbird-0:128.10.0-1.el8_6",
    "thunderbird-0:128.10.0-1.el9_5",
    "thunderbird-0:128.10.0-1.el10_0",
    "thunderbird-0:128.10.0-1.el9_2",
    "firefox-0:128.10.0-1.el9_4",
    "thunderbird-0:128.10.0-1.el8_4",
    "firefox-0:128.10.0-1.el8_6",
    "firefox-0:128.10.0-1.el9_5",
    "firefox-0:128.10.0-1.el9_6",
    "thunderbird-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el7_9",
    "thunderbird-0:128.10.0-1.el8_2",
    "firefox-0:128.10.0-1.el8_8",
    "firefox-0:128.10.0-1.el8_10",
    "thunderbird-0:128.10.0-1.el8_10",
    "firefox-0:128.10.0-1.el10_0",
    "firefox-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el8_2",
    "thunderbird-0:128.10.0-1.el8_8"
  ],
  "bugzilla": "2362902",
  "bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
  "cvss3_score": "8.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T13:13:33Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
  "severity": "important"
}
—
Product
product
NVDFirefox
receipt
Source
NVD
Its words
Firefox
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.23",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
                "versionEndExcluding": "115.23.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
                "versionEndExcluding": "138.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
                "versionEndExcluding": "128.10.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
                "versionEndExcluding": "128.10.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
                "versionEndExcluding": "138.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
      },
      {
        "lang": "es",
        "value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
      }
    ],
    "id": "CVE-2025-2817",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-2817",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T03:56:27.621494Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T14:15:32.220",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-2817",
  "CWE": "CWE-94",
  "advisories": [
    "RHSA-2025:7690",
    "RHSA-2025:7691",
    "RHSA-2025:7692",
    "RHSA-2025:7693",
    "RHSA-2025:7694",
    "RHSA-2025:7695",
    "RHSA-2025:7543",
    "RHSA-2025:4756",
    "RHSA-2025:4458",
    "RHSA-2025:7544",
    "RHSA-2025:7545",
    "RHSA-2025:4797",
    "RHSA-2025:7689",
    "RHSA-2025:4753",
    "RHSA-2025:7547",
    "RHSA-2025:4752",
    "RHSA-2025:4751",
    "RHSA-2025:4443",
    "RHSA-2025:7428",
    "RHSA-2025:7506",
    "RHSA-2025:7507",
    "RHSA-2025:4460"
  ],
  "affected_packages": [
    "firefox-0:128.10.0-1.el9_2",
    "thunderbird-0:128.10.0-1.el9_4",
    "firefox-0:128.10.0-1.el8_4",
    "thunderbird-0:128.10.0-1.el8_6",
    "thunderbird-0:128.10.0-1.el9_5",
    "thunderbird-0:128.10.0-1.el10_0",
    "thunderbird-0:128.10.0-1.el9_2",
    "firefox-0:128.10.0-1.el9_4",
    "thunderbird-0:128.10.0-1.el8_4",
    "firefox-0:128.10.0-1.el8_6",
    "firefox-0:128.10.0-1.el9_5",
    "firefox-0:128.10.0-1.el9_6",
    "thunderbird-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el7_9",
    "thunderbird-0:128.10.0-1.el8_2",
    "firefox-0:128.10.0-1.el8_8",
    "firefox-0:128.10.0-1.el8_10",
    "thunderbird-0:128.10.0-1.el8_10",
    "firefox-0:128.10.0-1.el10_0",
    "firefox-0:128.10.0-1.el9_0",
    "firefox-0:128.10.0-1.el8_2",
    "thunderbird-0:128.10.0-1.el8_8"
  ],
  "bugzilla": "2362902",
  "bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
  "cvss3_score": "8.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-04-29T13:13:33Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
  "severity": "important"
}
high
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.23",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
                "versionEndExcluding": "115.23.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
                "versionEndExcluding": "138.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
                "versionEndExcluding": "128.10.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
                "versionEndExcluding": "128.10.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
                "versionEndExcluding": "138.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
      },
      {
        "lang": "es",
        "value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
      }
    ],
    "id": "CVE-2025-2817",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-2817",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T03:56:27.621494Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T14:15:32.220",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDMozilla
receipt
Source
NVD
Its words
Mozilla
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "115.*",
                "status": "unaffected",
                "version": "115.23",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.10",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "138",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
                "versionEndExcluding": "115.23.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
                "matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
                "versionEndExcluding": "138.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
                "versionEndExcluding": "128.10.0",
                "versionStartIncluding": "116.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
                "versionEndExcluding": "128.10.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
                "versionEndExcluding": "138.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
      },
      {
        "lang": "es",
        "value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
      }
    ],
    "id": "CVE-2025-2817",
    "lastModified": "2026-09-30T18:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-2817",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-04-30T03:56:27.621494Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-04-29T14:15:32.220",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-22"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

firefox: thunderbird: Privilege escalation in Firefox Updater
zetlyn/cve-redhat · 2025-04-29
cvss 8.5 cwe CWE-94 packages firefox-0:128.10.0-1.el9_2, thunderbird-0:128.10.0-1.el9_4, firefox-0:128.10.0-1.el8_4, thunderbird-0:128.10.0-1.el8_6, thunderbird-0:128.10.0-1.el9_5, thunderbird-0:128.10.0-1.el10_0, thunderbird-0:128.10.0-1.el9_2, firefox-0:128.10.0-1.el9_4, thunderbird-0:128.10.0-1.el8_4, firefox-0:128.10.0-1.el8_6, firefox-0:128.10.0-1.el9_5, firefox-0:128.10.0-1.el9_6, thunderbird-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el7_9, thunderbird-0:128.10.0-1.el8_2, firefox-0:128.10.0-1.el8_8, firefox-0:128.10.0-1.el8_10, thunderbird-0:128.10.0-1.el8_10, firefox-0:128.10.0-1.el10_0, firefox-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el8_2, thunderbird-0:128.10.0-1.el8_8 severity important source
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.
zetlyn/cve-nvd · 2025-04-29
cvss 8.8 product Firefox status Modified vendor Mozilla source