Impact
The Netmonitor component contains a flaw that, based on the description, is inferred to allow a local attacker to elevate privileges. This weakness is classified as a privilege‑escalation vulnerability, indicating that misused functionality can raise the privilege level of a process or user on the affected system.
Affected Systems
Mozilla Firefox versions prior to 146 and Firefox ESR 140.6, as well as Mozilla Thunderbird versions prior to 146 and Thunderbird ESR 140.6, are vulnerable. The flaw remains present in any installed instances of these applications that have not been updated to the specified fixed versions.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity threat. The EPSS score of less than 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can leverage local privilege escalation by interacting with the Netmonitor component.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN