CVE-2025-3522

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 601

Summary

CVE-2025-3522 is a vulnerability affecting Thunderbird versions prior to 137.0.2 and 128.9.2. The issue lies in Thunderbird's handling of the X-Mozilla-External-Attachment-URL header. When processing this header, Thunderbird does not validate or sanitize the URL, allowing it to reference internal resources such as chrome:// or file:// SMB shares. As a result, opening an email with a malicious URL can lead to hashed Windows credential leakage and potentially more serious security issues. Thunderbird accesses the URL to determine file size and navigates to it when the user clicks the attachment, making this a significant risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird

Affected Vendors

  • Mozilla