CVE-2025-14329
8.8Mozilla · Firefox, Thunderbird
A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated permissions.
Executive summary
A critical privilege escalation flaw in the Netmonitor component of Mozilla Firefox and Thunderbird exposes users to potential security compromises and requires immediate updates.
Vulnerability
This is a privilege escalation vulnerability within the Netmonitor component. Based on the CVSS vector (PR:N, UI:R), the attack is unauthenticated but requires user interaction to exploit.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to full system compromise if exploited. Successful exploitation allows an attacker to gain unauthorized privileges, potentially resulting in data exfiltration, the installation of malicious software, or unauthorized control over the affected application.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 146 or the ESR version 140.6 immediately to apply the necessary security patches.
Proactive Monitoring: Review browser and application logs for unusual Netmonitor activity or unexpected privilege changes within the application environment.
Compensating Controls: Ensure that users operate with the principle of least privilege, limiting the potential impact of an application-level compromise on the underlying operating system.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the nature of privilege escalation, this vulnerability poses a significant risk to organizational endpoints. Security teams should prioritize the deployment of the Mozilla updates across all managed devices. Failure to patch these applications leaves users vulnerable to potential code execution and system-wide security breaches.
More Mozilla CVEs
Sources
Originally found and disclosed by satrya wira yudha, per the CVE Program record.