CVE-2023-25738
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-25738 is a high-severity vulnerability affecting Firefox, Firefox ESR, and Thunderbird on Windows systems. The vulnerability was discovered by Mark and disclosed in February 2023. The issue affects Firefox versions before 110, Thunderbird versions before 102.8, and Firefox ESR versions before 102.8. The vulnerability stems from improper validation of members in the DEVMODEW struct set by printer device drivers (Mozilla Advisory, NVD).

Technical details

The vulnerability occurs when members of the DEVMODEW struct set by the printer device driver aren't properly validated, which could result in invalid values. These invalid values could cause the browser to attempt out-of-bounds access to related variables. The issue has a CVSS v3.1 base score of 6.5 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. The vulnerability is classified as CWE-125 (Out-of-bounds Read) (NVD).

Impact

The vulnerability could cause the browser to crash when attempting to print on Windows systems. The issue specifically affects Windows users when interacting with certain printer device drivers. The bug is limited to Windows operating systems; other operating systems are unaffected (Mozilla Advisory).

Mitigation and workarounds

The vulnerability was fixed in Firefox 110, Firefox ESR 102.8, and Thunderbird 102.8. The fix involved implementing proper validation of the DEVMODEW struct values and clearing the default DEVMODEW storage on failure to prevent subsequent reuse of uninitialized data. As a temporary workaround before updating, users experiencing crashes could switch to using generic printer drivers (Mozilla Bug).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48639HIGH7.3
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management