Impact
According to the updated description, this vulnerability is a privilege escalation flaw in the Application Update component of Mozilla Firefox and Thunderbird. It allows an attacker to gain elevated privileges on the host. Based on the updated description, it is inferred that a local user likely needs to trigger the update process to exploit it. The flaw is classified as CWE-250 and CWE-269.
Affected Systems
Mozilla Firefox versions prior to 154 and Mozilla Thunderbird versions prior to 154 are affected. The security fix was released in Firefox 154 and Thunderbird 154, so any installation of Firefox 154 or later, or Thunderbird 154 or later, is no longer vulnerable.
Risk and Exploitability
The CVSS score of 8.8 denotes a high severity for this flaw. EPSS of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Based on the updated description, it is inferred that a local user who can trigger the Application Update process may be able to elevate privileges.
OpenCVE Enrichment