Impact
This vulnerability arises from a flaw in the Data Loss Prevention component of Mozilla products, allowing a local user to raise privileges within the application. The weakness involves improper enforcement of access controls, as classified by CWE‑269, and could enable execution of code or access to restricted data within the affected software.
Affected Systems
The issue affects Mozilla Firefox and Mozilla Thunderbird versions prior to 153. Specifically, any installation of Firefox 152 or earlier or Thunderbird 152 or earlier running the Data Loss Prevention feature is vulnerable. The bug was fixed in Firefox 153 and Thunderbird 153.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local, requiring user interaction to trigger the DLP component and exploit the flaw.
OpenCVE Enrichment