Impact
This vulnerability arises from an invalid pointer in Firefox’s Graphics component that can corrupt memory and allow a user to elevate privileges. The flaw represents an improper memory handling weakness (CWE‑787) that can lead to undefined behavior. The impact is a local privilege escalation that could potentially enable a malicious user to gain higher system privileges, depending on application usage and system configuration. Based on the description, the likely attack path involves supplying a crafted graphic file that triggers the pointer error, but that inference is not explicitly stated in the input.
Affected Systems
Mozilla Firefox versions older than 155, as well as all ESR releases prior to Firefox ESR 115.40, ESR 140.15, and ESR 153.2, are affected. System administrators should review installed Firefox binaries to confirm whether they fall into the vulnerable version ranges.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Although a formal CVSS score is not provided, the nature of the flaw—memory corruption leading to privilege escalation—typically corresponds to a high severity rating. Without a publicly confirmed exploit, the exploitation probability remains uncertain, but the potential impact justifies timely remediation.
OpenCVE Enrichment