#VU103615 Input validation error in Mozilla Thunderbird - CVE-2025-1015

 

#VU103615 Input validation error in Mozilla Thunderbird - CVE-2025-1015

Published: February 4, 2025 / Updated: February 7, 2025


Vulnerability identifier: #VU103615
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2025-1015
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Mozilla Thunderbird
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input when handling the Address Book URI fields. A remote attacker create and export an address book containing a malicious payload in a field, trick the victim into clicking on the link after importing the address book and a web page inside Thunderbird.


Remediation

Install updates from vendor's website.

External links