Impact
The vulnerability is a privilege escalation in the Messaging System component of Mozilla Firefox and Thunderbird. The flaw allows an attacker to perform actions at a higher privilege level within the application by exploiting the messaging component. Successful exploitation could grant unauthorized access to privileged functions or sensitive data beyond the normal user boundary. (Based on the description, it is inferred that the vulnerability involves missing access control checks.)
Affected Systems
Mozilla Firefox and Thunderbird, including their ESR branches, are affected. Versions before Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird ESR 140.8 contain the flaw. All later releases include the fix.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical vulnerability. The EPSS score is below 1 %, indicating a low current exploitation probability, and it is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need to interact with the vulnerable messaging component, likely requiring local user access or the ability to inject crafted messages; network exposure is not explicitly stated. The threat arises from the ability to elevate privileges within the application.
OpenCVE Enrichment
Debian DLA
Debian DSA