LiveActive security incident?Get immediate response
CVE Record

CVE-2017-5425: The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions.

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2017-5425 is a Mozilla sandbox weakness affecting Firefox and Thunderbird before version 52 on OS X only. The Gecko Media Plugin sandbox could allow access to certain local files under /private/var, potentially exposing personal or temporary data.

Executive priority

Low immediate urgency for modern fleets, but remediate any legacy OS X systems still running Firefox or Thunderbird below 52. The risk is privacy-sensitive local data exposure, not confirmed active exploitation in the provided sources.

Technical view

The issue is in Gecko Media Plugin sandbox path matching. Specific regular-expression matches allowed local file access, and on OS X this included some /private/var subdirectories. Mozilla updated the behavior to block /private/var and its subdirectories. Other operating systems are listed as unaffected.

Likely exposure

Exposure is limited to OS X systems running Firefox below 52 or Thunderbird below 52. Environments using current Mozilla versions, non-OS X platforms, or systems without these products are not indicated as affected by the provided sources.

Exploitation context

The bundle does not cite KEV status or public active exploitation. Treat this as a local data exposure risk from outdated Mozilla software rather than an internet-wide remote compromise based on the provided evidence.

Researcher notes

Key uncertainty is severity: the bundle provides no CVSS, CWE, or exploit evidence. Analysis should stay scoped to OS X, Gecko Media Plugin sandbox file access, /private/var exposure, and Mozilla Firefox/Thunderbird versions below 52.

Mitigation direction

  • Upgrade Firefox to version 52 or later where applicable.
  • Upgrade Thunderbird to version 52 or later where applicable.
  • Prioritize remaining OS X endpoints with legacy Mozilla installations.
  • Check Mozilla advisory guidance for any environment-specific instructions.

Validation and detection

  • Inventory OS X endpoints for Firefox and Thunderbird installations.
  • Confirm installed versions are not below 52.
  • Review exception lists for legacy OS X systems or unmanaged devices.
  • Verify vulnerability scanners use Mozilla product version detection, not OS-wide assumptions.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-5425 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MozillaFirefoxunspecifiedListed
MozillaThunderbirdunspecifiedListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.