Impact
A local privilege escalation flaw exists in the Netmonitor component of Mozilla Firefox and Thunderbird. The vulnerability, identified as CWE‑266, allows a user with local privileges to bypass the application’s privilege model and obtain higher system rights. The attacker could run arbitrary code, alter system files, or access sensitive data.
Affected Systems
Mozilla Firefox and its ESR line, as well as Mozilla Thunderbird and its ESR line, are affected. Versions released before Firefox 149 and before Firefox ESR 140.9 contain the flaw, as do Thunderbird versions before 149 and before Thunderbird ESR 140.9. Users on those releases should upgrade to the latest versions.
Risk and Exploitability
The CVSS base score of 9.8 signals a high severity, yet the EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalogue. Based on the description, it is inferred that the attack requires a local user who can launch Netmonitor or run code within the application context. Prompt patching is advised because of the high severity, even though current exploit probability remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA