CVE-2025-14328

8.8

Mozilla · Firefox, Thunderbird

A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated control.

Executive summary

A critical privilege escalation vulnerability in the Netmonitor component of Mozilla Firefox and Thunderbird exposes users to potential system compromise.

Vulnerability

The vulnerability exists within the Netmonitor component of the affected applications. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:R), this flaw can be triggered by an unauthenticated attacker through user interaction.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high level of risk to organizational security. Successful exploitation could lead to unauthorized privilege escalation, allowing an attacker to bypass security boundaries, access sensitive data, or perform actions with the permissions of the affected user, potentially resulting in significant reputational damage and data loss.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 140.6 or 146, or the latest available stable release, to apply the necessary security fixes.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unauthorized attempts to access sensitive system files following browser updates.

Compensating Controls: Ensure that endpoint protection software is active and configured to block malicious scripts, and enforce the principle of least privilege for all local user accounts to limit the potential impact of successful escalation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the critical nature of privilege escalation flaws in web browsers, immediate remediation is required. Organizations should prioritize patching all instances of Firefox and Thunderbird across their infrastructure to eliminate this exposure and prevent potential exploitation by malicious actors.

More Mozilla CVEs

Sources

Originally found and disclosed by Ameen Basha M K, per the CVE Program record.