Security readout for executives and security teams
Plain-English summary
CVE-2017-5425 is a Mozilla sandbox weakness affecting Firefox and Thunderbird before version 52 on OS X only. The Gecko Media Plugin sandbox could allow access to certain local files under /private/var, potentially exposing personal or temporary data.
Executive priority
Low immediate urgency for modern fleets, but remediate any legacy OS X systems still running Firefox or Thunderbird below 52. The risk is privacy-sensitive local data exposure, not confirmed active exploitation in the provided sources.
Technical view
The issue is in Gecko Media Plugin sandbox path matching. Specific regular-expression matches allowed local file access, and on OS X this included some /private/var subdirectories. Mozilla updated the behavior to block /private/var and its subdirectories. Other operating systems are listed as unaffected.
Likely exposure
Exposure is limited to OS X systems running Firefox below 52 or Thunderbird below 52. Environments using current Mozilla versions, non-OS X platforms, or systems without these products are not indicated as affected by the provided sources.
Exploitation context
The bundle does not cite KEV status or public active exploitation. Treat this as a local data exposure risk from outdated Mozilla software rather than an internet-wide remote compromise based on the provided evidence.
Researcher notes
Key uncertainty is severity: the bundle provides no CVSS, CWE, or exploit evidence. Analysis should stay scoped to OS X, Gecko Media Plugin sandbox file access, /private/var exposure, and Mozilla Firefox/Thunderbird versions below 52.
Mitigation direction
- Upgrade Firefox to version 52 or later where applicable.
- Upgrade Thunderbird to version 52 or later where applicable.
- Prioritize remaining OS X endpoints with legacy Mozilla installations.
- Check Mozilla advisory guidance for any environment-specific instructions.
Validation and detection
- Inventory OS X endpoints for Firefox and Thunderbird installations.
- Confirm installed versions are not below 52.
- Review exception lists for legacy OS X systems or unmanaged devices.
- Verify vulnerability scanners use Mozilla product version detection, not OS-wide assumptions.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-5425 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.mozilla.org/security/advisories/mfsa2017-09/CVE reference · x_refsource_CONFIRM
- https://www.mozilla.org/security/advisories/mfsa2017-05/CVE reference · x_refsource_CONFIRM
- https://bugzilla.mozilla.org/show_bug.cgi?id=1322716CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
