Impact
The Enterprise Policies component in Firefox and Thunderbird exposes a local privilege escalation flaw. A local attacker can use the component to elevate privileges within the application, which may allow them to perform operations reserved for privileged users. The issue is fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected Systems
Mozilla Firefox versions before 154 and Firefox ESR before 153.1, as well as Mozilla Thunderbird versions before 154 and Thunderbird ESR before 153.1, are impacted. All installations that have not applied the latest security updates are susceptible.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation at scale, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 9.8, so the risk is significant for any local user. The likely attack vector is local, requiring the attacker to already have accessed the user account or gained local code execution. Exploitation would allow the attacker to perform actions or modify settings that should be restricted to privileged users.
OpenCVE Enrichment