CVE-2025-3522 is a medium-severity vulnerability affecting Mozilla Thunderbird versions prior to 137.0.2 and 128.9.2. It arises from improper validation of the X-Mozilla-External-Attachment-URL header, allowing attackers to craft emails that reference internal resources like chrome:// or SMB file:// links. This can lead to the leakage of hashed Windows credentials and potentially more severe security issues when a user opens such an email or clicks the attachment. The vulnerability has a CVSS score of 6.3 (MEDIUM), indicating a network attack vector with low attack complexity, requiring user interaction. The potential impact includes low confidentiality, integrity, and availability. While the EPSS score is low, suggesting a lower likelihood of exploitation compared to many CVEs, the FAUCET Risk Score is 60/100. Currently, there is no known active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article identified, indicating limited public awareness or immediate threat perception.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 128.9.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
>= 129.0, < 137.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.