CVE-2025-2817
29.04.2025, 14:15
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 115.23.0 |
mozilla | firefox | 𝑥 < 138.0 |
mozilla | firefox | 116.0 ≤ 𝑥 < 128.10.0 |
mozilla | thunderbird | 𝑥 < 128.10.0 |
mozilla | thunderbird | 129.0 ≤ 𝑥 < 138.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
thunderbird |
|

Ubuntu Releases
References