Impact
The Netmonitor component contains a flaw that allows local users to elevate their privileges. The vulnerability enables them to execute actions or access resources beyond their intended authorization, which could compromise system integrity.
Affected Systems
Mozilla Firefox versions earlier than 146, and Firefox ESR versions earlier than 140.6, as well as Mozilla Thunderbird versions earlier than 146 and Thunderbird ESR versions earlier than 140.6, are affected. The Netmonitor component in these browsers is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of < 1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in CISA KEV, meaning no confirmed widespread exploitation has been documented. Likely exploitation requires local access to the system and the presence of the Netmonitor component. Once triggered, the attacker can gain higher privileges and potentially compromise the entire system.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN