
🚨 HIGH: CVE-2025-2817 (CVSS 8.8) Thunderbird update mechanism allows privilege escalation via file-locking manipulation. Attackers can achieve SYSTEM-level file operations from medium-integrity process. Patched in Thunderbird 138/128.10, Firefox 138/ESR. #CVE #PatchNow https://t.co/ysnn3uubAp
Post summary
Thunderbird and Firefox have released patches for CVE-2025-2817, a privilege‑escalation flaw using file‑locking manipulation; the post contains no evidence of active exploitation or a PoC.
