Impact
Internally discovered bugs in Thunderbird 154 and the corresponding ESR releases (ESR 153.1 and ESR 140.14) exhibited memory corruption or other security‑relevant defects. If successfully exploited, these flaws could allow an attacker to execute arbitrary code on the affected systems, potentially compromising confidentiality, integrity, or availability.
Affected Systems
The vulnerable builds are Thunderbird 154, ESR 153.1, and ESR 140.14, along with the matching Firefox releases. The issue is resolved in Thunderbird 155, ESR 153.2, and ESR 140.15, and in Firefox 155, ESR 115.40, ESR 140.15, and ESR 153.2. Updating to any of these releases removes the vulnerability.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild. The likely attack vector is local user interaction with untrusted data, such as a crafted email or web content, to trigger memory corruption. If an attacker succeeds, arbitrary code execution and full system compromise are possible. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
Debian DLA
Debian DSA