CVE-2025-3032

HIGH

Firefox < 137.0 and Thunderbird < 137.0 - File Descriptor Leak via Fork Server

Title source: llm
STIX 2.1

Description

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

References (3)

Core 3

Scores

CVSS v3 7.4
EPSS 0.0019
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-403
Status published
Products (4)
mozilla/firefox < 137.0
Mozilla/Firefox 137
mozilla/thunderbird < 137.0
Mozilla/Thunderbird 137
Published Apr 01, 2025
Tracked Since Feb 18, 2026