Impact
This vulnerability is a use-after-free flaw in the Audio/Video component of Mozilla Firefox. The flaw allows an attacker to access freed memory, potentially enabling arbitrary code execution. If exploited, the attacker could gain full control of the affected system, compromising confidentiality, integrity, and availability. The weakness is identified as a memory corruption issue, which falls into the common weakness category of use-after-free.
Affected Systems
The affected product is Mozilla Firefox. Versions prior to Firefox 155, Firefox ESR 115.40, ESR 140.15, and ESR 153.2 are vulnerable and have the issue fixed in the releases mentioned. Users running these earlier versions are at risk.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not disclosed, but use-after-free vulnerabilities typically have a high severity rating. The likely attack vector is the delivery of malicious audio or video content, which an attacker can trigger through a web page or local media file. Without a patch, exploitation remains possible and could lead to arbitrary code execution.
OpenCVE Enrichment