CVE-2025-2817 Information

Description

Mozilla Firefox’s update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process an attacker could bypass intended access controls allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138 Firefox ESR < 128.10 Firefox ESR < 115.23 Thunderbird < 138 and Thunderbird ESR < 128.10.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1917536 https://www.mozilla.org/security/advisories/mfsa2025-28/ https://www.mozilla.org/security/advisories/mfsa2025-29/ https://www.mozilla.org/security/advisories/mfsa2025-30/ https://www.mozilla.org/security/advisories/mfsa2025-31/ https://www.mozilla.org/security/advisories/mfsa2025-32/

Share on: