Impact
Internally discovered bugs in Thunderbird 154 and Thunderbird ESR 153.1 caused memory corruption or other security‑relevant defects. These defects fall under the memory‑corruption weakness represented by CWE-119, and could allow an attacker with sufficient effort to execute arbitrary code within the Thunderbird process, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Thunderbird 154 and Thunderbird ESR 153.1 are affected. The same bugs were fixed in Firefox 155 and Firefox ESR 153.2, indicating that earlier releases of Firefox—those older than 155 or ESR 153.2—are likely vulnerable as well. Systems running these older Thunderbird or Firefox releases remain at risk until updated to the fixed versions.
Risk and Exploitability
The CVSS score of 7.5 and an EPSS score of <1% suggest a moderate severity with a currently low known exploitation probability. The vulnerability is not listed in CISA KEV. Based on typical exploitation methods for memory corruption in email clients, the likely attack vector is delivery of malicious email content or web material that triggers the underlying bug. An attacker would need to devise content designed to exploit the memory corruption; no public exploitation has been observed yet, but the theoretical risk remains.
OpenCVE Enrichment