QID 375529

Date Published: 2021-05-10

QID 375529: Mozilla Thunderbird Security Restriction Bypass Vulnerability (MFSA2021-19)

Thunderbird is a free and open-source cross-platform email client developed for Windows, OS X, and Linux, with a mobile version for Android.

Affected Products:
Prior to Mozilla Thunderbird 78.10.1
Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected

QID Detection Logic (Authenticated):
This checks for vulnerable version of Thunderbird.

Successful exploitation of this vulnerability may allow an attacker to start or stop Thunderbird maintenance service as a domain user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to MFSA2021-19

    CVEs related to QID 375529

    Software Advisories
    Advisory ID Software Component Link
    MFSA2021-19 URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-19/