Impact
Malicious calendar invitations can contain file URI attachments that trigger the launch of local or network‑hosted executables on Windows while bypassing Thunderbird’s normal executable attachment protections. The effect is local code execution, enabling an attacker to run arbitrary binaries if a user accepts such an invitation; this can result in a local privilege escalation if the user has elevated rights. The weakness reflects improper validation and handling of executable attachments, allowing an unauthenticated user to cause the application to execute local code.
Affected Systems
Mozilla’s Thunderbird email client is affected. Versions older than Thunderbird 154 and 153.2 are vulnerable, as the fix was applied in those releases. Users running any earlier Thunderbird build—regardless of platform—remain at risk. The issue specifically involves the new invitation display feature introduced in recent Thunderbird updates.
Risk and Exploitability
No CVSS or EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is user‑dependent: a malicious calendar invite must be opened to trigger execution, so remote exploitation is not possible. While no active exploits have been reported and the EPSS is unavailable, the local code execution risk remains high for users who routinely accept calendar invitations. Organizations should monitor for suspicious calendar activity and consider adding additional scrutiny of file URI attachments.
OpenCVE Enrichment