firefox: thunderbird: Privilege escalation in Firefox Updater
cve CVE-2025-2817 2 sources, 2 claims · Watch
What it is to other things
| affects | mozilla/firefox NVD |
| affects | mozilla/thunderbird NVD |
| made_by | mozilla NVD |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss conflict | NVD | 8.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "115.*",
"status": "unaffected",
"version": "115.23",
"versionType": "rpm"
},
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
"versionEndExcluding": "115.23.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
"versionEndExcluding": "138.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
"versionEndExcluding": "128.10.0",
"versionStartIncluding": "116.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
"versionEndExcluding": "128.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
"versionEndExcluding": "138.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
},
{
"lang": "es",
"value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
}
],
"id": "CVE-2025-2817",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2817",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-30T03:56:27.621494Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-04-29T14:15:32.220",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-22"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Cvss cvss conflict | Red Hat | 8.5receipt
What the source handed over{
"CVE": "CVE-2025-2817",
"CWE": "CWE-94",
"advisories": [
"RHSA-2025:7690",
"RHSA-2025:7691",
"RHSA-2025:7692",
"RHSA-2025:7693",
"RHSA-2025:7694",
"RHSA-2025:7695",
"RHSA-2025:7543",
"RHSA-2025:4756",
"RHSA-2025:4458",
"RHSA-2025:7544",
"RHSA-2025:7545",
"RHSA-2025:4797",
"RHSA-2025:7689",
"RHSA-2025:4753",
"RHSA-2025:7547",
"RHSA-2025:4752",
"RHSA-2025:4751",
"RHSA-2025:4443",
"RHSA-2025:7428",
"RHSA-2025:7506",
"RHSA-2025:7507",
"RHSA-2025:4460"
],
"affected_packages": [
"firefox-0:128.10.0-1.el9_2",
"thunderbird-0:128.10.0-1.el9_4",
"firefox-0:128.10.0-1.el8_4",
"thunderbird-0:128.10.0-1.el8_6",
"thunderbird-0:128.10.0-1.el9_5",
"thunderbird-0:128.10.0-1.el10_0",
"thunderbird-0:128.10.0-1.el9_2",
"firefox-0:128.10.0-1.el9_4",
"thunderbird-0:128.10.0-1.el8_4",
"firefox-0:128.10.0-1.el8_6",
"firefox-0:128.10.0-1.el9_5",
"firefox-0:128.10.0-1.el9_6",
"thunderbird-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el7_9",
"thunderbird-0:128.10.0-1.el8_2",
"firefox-0:128.10.0-1.el8_8",
"firefox-0:128.10.0-1.el8_10",
"thunderbird-0:128.10.0-1.el8_10",
"firefox-0:128.10.0-1.el10_0",
"firefox-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el8_2",
"thunderbird-0:128.10.0-1.el8_8"
],
"bugzilla": "2362902",
"bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
"cvss3_score": "8.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-04-29T13:13:33Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
"severity": "important"
} | — |
| Cwe cwe | Red Hat | CWE-94receipt
What the source handed over{
"CVE": "CVE-2025-2817",
"CWE": "CWE-94",
"advisories": [
"RHSA-2025:7690",
"RHSA-2025:7691",
"RHSA-2025:7692",
"RHSA-2025:7693",
"RHSA-2025:7694",
"RHSA-2025:7695",
"RHSA-2025:7543",
"RHSA-2025:4756",
"RHSA-2025:4458",
"RHSA-2025:7544",
"RHSA-2025:7545",
"RHSA-2025:4797",
"RHSA-2025:7689",
"RHSA-2025:4753",
"RHSA-2025:7547",
"RHSA-2025:4752",
"RHSA-2025:4751",
"RHSA-2025:4443",
"RHSA-2025:7428",
"RHSA-2025:7506",
"RHSA-2025:7507",
"RHSA-2025:4460"
],
"affected_packages": [
"firefox-0:128.10.0-1.el9_2",
"thunderbird-0:128.10.0-1.el9_4",
"firefox-0:128.10.0-1.el8_4",
"thunderbird-0:128.10.0-1.el8_6",
"thunderbird-0:128.10.0-1.el9_5",
"thunderbird-0:128.10.0-1.el10_0",
"thunderbird-0:128.10.0-1.el9_2",
"firefox-0:128.10.0-1.el9_4",
"thunderbird-0:128.10.0-1.el8_4",
"firefox-0:128.10.0-1.el8_6",
"firefox-0:128.10.0-1.el9_5",
"firefox-0:128.10.0-1.el9_6",
"thunderbird-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el7_9",
"thunderbird-0:128.10.0-1.el8_2",
"firefox-0:128.10.0-1.el8_8",
"firefox-0:128.10.0-1.el8_10",
"thunderbird-0:128.10.0-1.el8_10",
"firefox-0:128.10.0-1.el10_0",
"firefox-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el8_2",
"thunderbird-0:128.10.0-1.el8_8"
],
"bugzilla": "2362902",
"bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
"cvss3_score": "8.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-04-29T13:13:33Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
"severity": "important"
} | — |
| Packages packages | Red Hat | firefox-0:128.10.0-1.el9_2, thunderbird-0:128.10.0-1.el9_4, firefox-0:128.10.0-1.el8_4, thunderbird-0:128.10.0-1.el8_6, thunderbird-0:128.10.0-1.el9_5, thunderbird-0:128.10.0-1.el10_0, thunderbird-0:128.10.0-1.el9_2, firefox-0:128.10.0-1.el9_4, thunderbird-0:128.10.0-1.el8_4, firefox-0:128.10.0-1.el8_6, firefox-0:128.10.0-1.el9_5, firefox-0:128.10.0-1.el9_6, thunderbird-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el7_9, thunderbird-0:128.10.0-1.el8_2, firefox-0:128.10.0-1.el8_8, firefox-0:128.10.0-1.el8_10, thunderbird-0:128.10.0-1.el8_10, firefox-0:128.10.0-1.el10_0, firefox-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el8_2, thunderbird-0:128.10.0-1.el8_8receipt
What the source handed over{
"CVE": "CVE-2025-2817",
"CWE": "CWE-94",
"advisories": [
"RHSA-2025:7690",
"RHSA-2025:7691",
"RHSA-2025:7692",
"RHSA-2025:7693",
"RHSA-2025:7694",
"RHSA-2025:7695",
"RHSA-2025:7543",
"RHSA-2025:4756",
"RHSA-2025:4458",
"RHSA-2025:7544",
"RHSA-2025:7545",
"RHSA-2025:4797",
"RHSA-2025:7689",
"RHSA-2025:4753",
"RHSA-2025:7547",
"RHSA-2025:4752",
"RHSA-2025:4751",
"RHSA-2025:4443",
"RHSA-2025:7428",
"RHSA-2025:7506",
"RHSA-2025:7507",
"RHSA-2025:4460"
],
"affected_packages": [
"firefox-0:128.10.0-1.el9_2",
"thunderbird-0:128.10.0-1.el9_4",
"firefox-0:128.10.0-1.el8_4",
"thunderbird-0:128.10.0-1.el8_6",
"thunderbird-0:128.10.0-1.el9_5",
"thunderbird-0:128.10.0-1.el10_0",
"thunderbird-0:128.10.0-1.el9_2",
"firefox-0:128.10.0-1.el9_4",
"thunderbird-0:128.10.0-1.el8_4",
"firefox-0:128.10.0-1.el8_6",
"firefox-0:128.10.0-1.el9_5",
"firefox-0:128.10.0-1.el9_6",
"thunderbird-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el7_9",
"thunderbird-0:128.10.0-1.el8_2",
"firefox-0:128.10.0-1.el8_8",
"firefox-0:128.10.0-1.el8_10",
"thunderbird-0:128.10.0-1.el8_10",
"firefox-0:128.10.0-1.el10_0",
"firefox-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el8_2",
"thunderbird-0:128.10.0-1.el8_8"
],
"bugzilla": "2362902",
"bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
"cvss3_score": "8.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-04-29T13:13:33Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
"severity": "important"
} | — |
| Product product | NVD | Firefoxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "115.*",
"status": "unaffected",
"version": "115.23",
"versionType": "rpm"
},
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
"versionEndExcluding": "115.23.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
"versionEndExcluding": "138.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
"versionEndExcluding": "128.10.0",
"versionStartIncluding": "116.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
"versionEndExcluding": "128.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
"versionEndExcluding": "138.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
},
{
"lang": "es",
"value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
}
],
"id": "CVE-2025-2817",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2817",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-30T03:56:27.621494Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-04-29T14:15:32.220",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-22"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2025-2817",
"CWE": "CWE-94",
"advisories": [
"RHSA-2025:7690",
"RHSA-2025:7691",
"RHSA-2025:7692",
"RHSA-2025:7693",
"RHSA-2025:7694",
"RHSA-2025:7695",
"RHSA-2025:7543",
"RHSA-2025:4756",
"RHSA-2025:4458",
"RHSA-2025:7544",
"RHSA-2025:7545",
"RHSA-2025:4797",
"RHSA-2025:7689",
"RHSA-2025:4753",
"RHSA-2025:7547",
"RHSA-2025:4752",
"RHSA-2025:4751",
"RHSA-2025:4443",
"RHSA-2025:7428",
"RHSA-2025:7506",
"RHSA-2025:7507",
"RHSA-2025:4460"
],
"affected_packages": [
"firefox-0:128.10.0-1.el9_2",
"thunderbird-0:128.10.0-1.el9_4",
"firefox-0:128.10.0-1.el8_4",
"thunderbird-0:128.10.0-1.el8_6",
"thunderbird-0:128.10.0-1.el9_5",
"thunderbird-0:128.10.0-1.el10_0",
"thunderbird-0:128.10.0-1.el9_2",
"firefox-0:128.10.0-1.el9_4",
"thunderbird-0:128.10.0-1.el8_4",
"firefox-0:128.10.0-1.el8_6",
"firefox-0:128.10.0-1.el9_5",
"firefox-0:128.10.0-1.el9_6",
"thunderbird-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el7_9",
"thunderbird-0:128.10.0-1.el8_2",
"firefox-0:128.10.0-1.el8_8",
"firefox-0:128.10.0-1.el8_10",
"thunderbird-0:128.10.0-1.el8_10",
"firefox-0:128.10.0-1.el10_0",
"firefox-0:128.10.0-1.el9_0",
"firefox-0:128.10.0-1.el8_2",
"thunderbird-0:128.10.0-1.el8_8"
],
"bugzilla": "2362902",
"bugzilla_description": "firefox: thunderbird: Privilege escalation in Firefox Updater",
"cvss3_score": "8.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-04-29T13:13:33Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-2817.json",
"severity": "important"
} | high |
| Status status | NVD | Modifiedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "115.*",
"status": "unaffected",
"version": "115.23",
"versionType": "rpm"
},
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
"versionEndExcluding": "115.23.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
"versionEndExcluding": "138.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
"versionEndExcluding": "128.10.0",
"versionStartIncluding": "116.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
"versionEndExcluding": "128.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
"versionEndExcluding": "138.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
},
{
"lang": "es",
"value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
}
],
"id": "CVE-2025-2817",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2817",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-30T03:56:27.621494Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-04-29T14:15:32.220",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-22"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | Mozillareceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "115.*",
"status": "unaffected",
"version": "115.23",
"versionType": "rpm"
},
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.10",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "138",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "844477E0-B931-4583-94F3-2C9871DB0D07",
"versionEndExcluding": "115.23.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "EB8A8C7B-B65D-4DF5-BDB5-0C3C4E2DB72C",
"versionEndExcluding": "138.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "01B708BC-00EE-41A1-80B7-0C845DAE30E8",
"versionEndExcluding": "128.10.0",
"versionStartIncluding": "116.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "47A000D1-78D1-43A0-BBA8-5018439291D3",
"versionEndExcluding": "128.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBE9403-75DD-46EE-AD64-B950562130D1",
"versionEndExcluding": "138.0",
"versionStartIncluding": "129.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10."
},
{
"lang": "es",
"value": "El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138 y Thunderbird ESR < 128.10."
}
],
"id": "CVE-2025-2817",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2817",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-30T03:56:27.621494Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-04-29T14:15:32.220",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917536"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-28/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-29/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-30/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-31/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-32/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00022.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-22"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| firefox: thunderbird: Privilege escalation in Firefox Updater zetlyn/cve-redhat · 2025-04-29 | cvss 8.5 cwe CWE-94 packages firefox-0:128.10.0-1.el9_2, thunderbird-0:128.10.0-1.el9_4, firefox-0:128.10.0-1.el8_4, thunderbird-0:128.10.0-1.el8_6, thunderbird-0:128.10.0-1.el9_5, thunderbird-0:128.10.0-1.el10_0, thunderbird-0:128.10.0-1.el9_2, firefox-0:128.10.0-1.el9_4, thunderbird-0:128.10.0-1.el8_4, firefox-0:128.10.0-1.el8_6, firefox-0:128.10.0-1.el9_5, firefox-0:128.10.0-1.el9_6, thunderbird-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el7_9, thunderbird-0:128.10.0-1.el8_2, firefox-0:128.10.0-1.el8_8, firefox-0:128.10.0-1.el8_10, thunderbird-0:128.10.0-1.el8_10, firefox-0:128.10.0-1.el10_0, firefox-0:128.10.0-1.el9_0, firefox-0:128.10.0-1.el8_2, thunderbird-0:128.10.0-1.el8_8 severity important | source |
| Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10. zetlyn/cve-nvd · 2025-04-29 | cvss 8.8 product Firefox status Modified vendor Mozilla | source |