CVE-2025-3032
🟡 Monitoruj
Wyciekanie deskryptorów plików w Firefoxie umożliwia ataki eskalacji uprawnień.
CVSS
7.4
EPSS
0.4%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-04-01 13:15:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 18:10:00 UTC |
Referencje
- https://bugzilla.mozilla.org/show_bug.cgi?id=1949987 ([email protected]) [Issue Tracking, Permissions Required]
- https://www.mozilla.org/security/advisories/mfsa2025-20/ ([email protected]) [Vendor Advisory]
- https://www.mozilla.org/security/advisories/mfsa2025-23/ ([email protected]) [Vendor Advisory]