Impact
The vulnerability consists of a set of internally discovered bugs that were present in Thunderbird ESR 140.13, Thunderbird ESR 153.0, and Thunderbird 153. Some of these bugs involve memory corruption or other security-relevant defects. The description indicates that, with sufficient effort, some of these could be exploited, potentially enabling arbitrary code execution. The fixes were applied in Thunderbird 154, Thunderbird ESR 140.14, and Thunderbird ESR 153.1.
Affected Systems
Affected systems are Mozilla's Thunderbird email client, specifically the Extended Support Release 140.13, the Extended Support Release 153.0, and the standard Thunderbird 153 release, as well as Mozilla Firefox older than version 154 (including releases prior to the Firefox ESR 140.14 and ESR 153.1). These bugs were corrected in subsequent releases: Thunderbird ESR 140.14, ESR 153.1, and Thunderbird 154, and Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1; users running earlier builds are at risk until they update.
Risk and Exploitability
Risk assessment can rely on the CVSS score of 9.8, which indicates a high severity of potential arbitrary code execution via memory corruption. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploits yet. Memory‑corruption vulnerabilities are high risk as they may enable arbitrary code execution if an attacker can trigger them; the likely attack vector could be remote or local, depending on how the corruption is triggered, though this is inferred because the description does not specify the exact trigger.
OpenCVE Enrichment
Debian DLA
Debian DSA