Impact
The Remote Settings Client component has a flaw that enables an attacker to elevate privileges. When exploited, the vulnerability lets an attacker perform operations with higher authority than intended, compromising both the integrity and the confidentiality of the user’s browser session and potentially the underlying system. The weakness reflects an improper authorization error (CWE‑269) and a deficiency in privilege separation (CWE‑266), which together allow unauthorized privilege escalation.
Affected Systems
Mozilla Firefox (versions 154 and the ESR releases 115.39, 140.14, 153.1) and Mozilla Thunderbird (versions 154 and the ESR releases 140.14, 153.1) are affected. Clients running any of these or older releases lack the necessary patch to mitigate the flaw.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity vulnerability. The EPSS score is < 1%, suggesting a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring the attacker to supply crafted Remote Settings data. Without remediation, an attacker who successfully exploits the flaw could gain elevated permissions, with the precise impact depending on the system configuration.
OpenCVE Enrichment
Debian DLA
Debian DSA