Security Vulnerability Report
中文
CVE-2025-14328 CVSS 8.8 HIGH

CVE-2025-14328

Published: 2025-12-09 16:17:40
Last Modified: 2026-04-13 15:16:46

Description

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* - VULNERABLE
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* - VULNERABLE
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* - VULNERABLE
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* - VULNERABLE
Firefox < 146
Firefox ESR < 140.6
Thunderbird < 146
Thunderbird ESR < 140.6

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2025-14328 PoC - Netmonitor Privilege Escalation // Note: This is a conceptual PoC based on the vulnerability description // Actual exploitation requires specific conditions and browser version // The vulnerability allows privilege escalation through Netmonitor component // Attackers can craft malicious pages that leverage Netmonitor's elevated privileges // Conceptual attack flow: function exploitNetmonitorVulnerability() { // Step 1: Prepare malicious payload const maliciousPayload = { action: 'privilege_escalation', target: 'netmonitor_component', exploit: 'cross_context_access' }; // Step 2: Trigger Netmonitor component // This would typically involve specific interactions with Netmonitor // that expose the privilege escalation vector // Step 3: Execute privileged operations // The actual PoC would contain specific code to: // - Bypass security checks in Netmonitor // - Execute code with elevated privileges // - Access restricted resources return 'PoC demonstrates privilege escalation via Netmonitor'; } // Note: Full PoC requires browser-specific debugging tools and // specific Firefox/Thunderbird version targeting // Reference: https://bugzilla.mozilla.org/show_bug.cgi?id=1996761

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-14328", "sourceIdentifier": "[email protected]", "published": "2025-12-09T16:17:40.333", "lastModified": "2026-04-13T15:16:46.140", "vulnStatus": "Modified", "cveTags": [], "descriptions": [{"lang": "en", "value": "Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6."}], "metrics": {"cvssMetricV31": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*", "versionEndExcluding": "140.6.0", "matchCriteriaId": "A580DBD9-518B-4261-9FA8-DDFB1C5175E1"}, {"vulnerable": true, "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*", "versionEndExcluding": "146.0", "matchCriteriaId": "3EF4CBBC-DCB5-4540-8B8A-91DA759ED631"}, {"vulnerable": true, "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*", "versionEndExcluding": "140.6.0", "matchCriteriaId": "F04F8674-52CC-4217-B94A-8C5E80C5B996"}, {"vulnerable": true, "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*", "versionEndExcluding": "146.0", "matchCriteriaId": "1CB46BC7-512D-45BF-BCF4-73FDDF94DBAF"}]}]}], "references": [{"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1996761", "source": "[email protected]", "tags": ["Issue Tracking", "Permissions Required"]}, {"url": "https://www.mozilla.org/security/advisories/mfsa2025-92/", "source": "[email protected]", "tags": ["Vendor Advisory"]}, {"url": "https://www.mozilla.org/security/advisories/mfsa2025-94/", "source": "[email protected]", "tags": ["Vendor Advisory"]}, {"url": "https://www.mozilla.org/security/advisories/mfsa2025-95/", "source": "[email protected]", "tags": ["Vendor Advisory"]}, {"url": "https://www.mozilla.org/security/advisories/mfsa2025-96/", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}