Leak of hashed Window credentials via crafted attachment URL
Published Apr 15, 2025
7.4
HIGHCVSS 3.1
EPSS 0.27%
Description
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Affected products
No data.
- < 128.9.2
- ≥ 129.0 · < 137.0.2
No data.
Red Hat Enterprise Linux 10
thunderbird-0:128.10.0-1.el10_0
Fixed · RHSA-2025:7507
Red Hat Enterprise Linux 8
thunderbird-0:128.9.2-1.el8_10
Fixed · RHSA-2025:4649
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:128.9.2-1.el8_2
Fixed · RHSA-2025:4389
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:128.9.2-1.el8_4
Fixed · RHSA-2025:4654
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
thunderbird-0:128.9.2-1.el8_4
Fixed · RHSA-2025:4654
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
thunderbird-0:128.9.2-1.el8_4
Fixed · RHSA-2025:4654
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
thunderbird-0:128.9.2-1.el8_6
Fixed · RHSA-2025:4665
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
thunderbird-0:128.9.2-1.el8_6
Fixed · RHSA-2025:4665
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
thunderbird-0:128.9.2-1.el8_6
Fixed · RHSA-2025:4665
Red Hat Enterprise Linux 8.8 Extended Update Support
thunderbird-0:128.9.2-1.el8_8
Fixed · RHSA-2025:4617
Red Hat Enterprise Linux 9
thunderbird-0:128.10.0-1.el9_6
Fixed · RHSA-2025:7435
Red Hat Enterprise Linux 9
thunderbird-0:128.9.2-1.el9_5
Fixed · RHSA-2025:4229
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
thunderbird-0:128.9.2-1.el9_0
Fixed · RHSA-2025:4514
Red Hat Enterprise Linux 9.2 Extended Update Support
thunderbird-0:128.9.2-1.el9_2
Fixed · RHSA-2025:4513
Red Hat Enterprise Linux 9.4 Extended Update Support
thunderbird-0:128.9.2-1.el9_4
Fixed · RHSA-2025:4512
Red Hat Enterprise Linux 10
thunderbird-flatpak-container
Affected
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
Red Hat Enterprise Linux 9
thunderbird-flatpak-container
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | thunderbird-0:128.10.0-1.el10_0 | Fixed | RHSA-2025:7507 |
| Red Hat Enterprise Linux 8 | thunderbird-0:128.9.2-1.el8_10 | Fixed | RHSA-2025:4649 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:128.9.2-1.el8_2 | Fixed | RHSA-2025:4389 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:128.9.2-1.el8_4 | Fixed | RHSA-2025:4654 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | thunderbird-0:128.9.2-1.el8_4 | Fixed | RHSA-2025:4654 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | thunderbird-0:128.9.2-1.el8_4 | Fixed | RHSA-2025:4654 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | thunderbird-0:128.9.2-1.el8_6 | Fixed | RHSA-2025:4665 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | thunderbird-0:128.9.2-1.el8_6 | Fixed | RHSA-2025:4665 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | thunderbird-0:128.9.2-1.el8_6 | Fixed | RHSA-2025:4665 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | thunderbird-0:128.9.2-1.el8_8 | Fixed | RHSA-2025:4617 |
| Red Hat Enterprise Linux 9 | thunderbird-0:128.10.0-1.el9_6 | Fixed | RHSA-2025:7435 |
| Red Hat Enterprise Linux 9 | thunderbird-0:128.9.2-1.el9_5 | Fixed | RHSA-2025:4229 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | thunderbird-0:128.9.2-1.el9_0 | Fixed | RHSA-2025:4514 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | thunderbird-0:128.9.2-1.el9_2 | Fixed | RHSA-2025:4513 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | thunderbird-0:128.9.2-1.el9_4 | Fixed | RHSA-2025:4512 |
| Red Hat Enterprise Linux 10 | thunderbird-flatpak-container | Affected | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | thunderbird-flatpak-container | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-3522 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1955372 Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=2359793 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10965 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-3522
- https://www.cve.org/CVERecord?id=CVE-2025-3522
- https://www.mozilla.org/security/advisories/mfsa2025-26/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-27/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-3522 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1955372 | Permissions Required | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2359793 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10965 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-3522 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-3522 | ||
| https://www.mozilla.org/security/advisories/mfsa2025-26/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2025-27/ | Vendor Advisory |
Change history (0)
No recorded changes yet.