CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.
Configurations

No configuration.

History

01 May 2025, 15:16

Type Values Removed Values Added
Summary
  • (es) El mecanismo de actualización de Mozilla Firefox permitía que un proceso de usuario de integridad media interfiriera con el actualizador a nivel de SYSTEM manipulando el comportamiento de bloqueo de archivos. Al inyectar código en el proceso con privilegios de usuario, un atacante podía eludir los controles de acceso previstos, lo que permitía operaciones con archivos a nivel de SYSTEM en rutas controladas por un usuario sin privilegios y habilitaba la escalada de privilegios. Esta vulnerabilidad afecta a Firefox &lt; 138, Firefox ESR &lt; 128.10, Firefox ESR &lt; 115.23, Thunderbird &lt; 138 y Thunderbird ESR &lt; 128.10.
Summary (en) Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10. (en) Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

29 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

29 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 14:15

Updated : 2025-05-02 13:53


NVD link : CVE-2025-2817

Mitre link : CVE-2025-2817

CVE.ORG link : CVE-2025-2817


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')