First published: Tue Apr 01 2025(Updated: )
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <137 | 137 |
Thunderbird | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-3032 has been classified as a high severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2025-3032, users should update Firefox and Thunderbird to version 137 or later.
CVE-2025-3032 affects Firefox versions less than 137 and Thunderbird versions less than 137.
CVE-2025-3032 allows for privilege escalation attacks through leaking file descriptors.
The vendor for CVE-2025-3032 is Mozilla, responsible for both Firefox and Thunderbird software.