Impact
This vulnerability arises from an invalid pointer in Firefox's and Thunderbird's Graphics component that can corrupt memory and allow a user to elevate privileges. The flaw represents improper memory handling weaknesses (CWE-763, CWE-825) that can lead to undefined behavior. The impact is a local privilege escalation that could potentially enable a malicious user to gain higher system privileges, depending on application usage and system configuration. Based on the description, the likely attack path involves supplying a crafted graphic file that triggers the pointer error, but that inference is not explicitly stated in the input.
Affected Systems
Mozilla Firefox versions older than 155, as well as all ESR releases prior to Firefox ESR 115.40, ESR 140.15, and ESR 153.2, are affected. Mozilla Thunderbird versions older than 155, and all ESR releases prior to Thunderbird ESR 115.40, 140.15, and 153.2, are also affected. System administrators should review installed Firefox and Thunderbird binaries to confirm whether they fall into the vulnerable version ranges.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. This memory corruption flaw results in privilege escalation; without a publicly confirmed exploit, the exploitation probability remains uncertain, yet the potential impact justifies timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA