Impact
A flaw in the request handling logic of Mozilla Firefox and Thunderbird allows an attacker to gain elevated privileges on the host. The vulnerability is classified as a privilege escalation weakness (CWE‑269) and an access control issue within a process (CWE‑551). No detailed exploitation path is supplied, but the description indicates that processing a malicious request can trigger the privilege elevation.
Affected Systems
Mozilla Firefox versions prior to 154 and the ESR branch before 153.1 are vulnerable, as are Mozilla Thunderbird releases prior to 154 and ESR before 153.1. The flaw resides in the request handling component common to these products.
Risk and Exploitability
The CVSS score of 8.8 places the vulnerability in the high‑severity category. The EPSS score is less than 1 %, indicating a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the flaw by crafting a malicious request that the browser processes, triggering the elevation of privileges.
OpenCVE Enrichment