CVE-2025-2817: Privilege escalation in Thunderbird Updater
Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation.
Other sources
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2817?
CVE-2025-2817 is classified as a medium severity vulnerability.
How do I fix CVE-2025-2817?
To fix CVE-2025-2817, update your Mozilla Firefox to version 138 or higher, or to Firefox ESR version 115.23 or higher.
What products are affected by CVE-2025-2817?
CVE-2025-2817 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to the specified updates.
What is the nature of the flaw in CVE-2025-2817?
The flaw in CVE-2025-2817 involves a vulnerable update mechanism that allows a medium-integrity user process to interfere with the SYSTEM-level updater.
Can CVE-2025-2817 allow unauthorized file operations?
Yes, CVE-2025-2817 can allow attackers to bypass access controls and perform SYSTEM-level file operations.