Impact
Malicious calendar invitations can embed file URI attachments that trigger the launch of local or network‑hosted executables on Windows, bypassing Thunderbird’s built‑in executable attachment protections. The flaw is rooted in insufficient validation and handling of executable attachments, allowing an unauthenticated attacker to induce the client to run code supplied in the invite. If a user opens such an invitation, arbitrary binaries are executed on the local machine.
Affected Systems
The vulnerability affects Mozilla’s Thunderbird email client versions older than 154 and 153.2. It applies to all platforms that run Thunderbird, though the described impact is limited to Windows where the local execution is possible. The issue was addressed in Thunderbird 154 and 153.2 through improved validation logic.
Risk and Exploitability
The CVSS score is 9.8, indicating a high‑severity flaw. The EPSS score is less than 1%, suggesting a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must forge a calendar invitation that a user opens; thus no remote exploitation is feasible without user interaction. No public exploits have been reported, but the risk remains for users who accept calendar invites. Organizations should monitor for suspicious calendar activity and ensure that affected Thunderbird installations are updated promptly.
OpenCVE Enrichment