Impact
This vulnerability allows an attacker to ascend privileges within Mozilla Firefox and Thunderbird by exploiting a flaw in the DOM navigation component. The issue involves CWE-269 and CWE-270, enabling an attacker to execute code with higher privileges than intended. The impact extends to any user interacting with affected web content or local files that trigger the buggy navigation logic.
Affected Systems
Mozilla Firefox versions before 153 and Mozilla Thunderbird before 153 are affected. Updating to Firefox 153 or newer, or Thunderbird 153 or newer, removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 marks the issue as high severity, yet the EPSS score is below 1%, indicating a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not provided, the issue resides in a browser’s DOM navigation component, so the most probable vectors involve malicious web content or a local attack that triggers the privilege escalation.
OpenCVE Enrichment