Impact
A flaw in the Graphics component creates incorrect boundary conditions that allow an attacker to elevate privileges. The vulnerability is capable of bypassing normal security controls, leading to escalation to higher user or system privileges. It is categorized as CWE-120 and CWE-787, indicating classic buffer overrun or related boundary errors that can be leveraged for privilege gain.
Affected Systems
Mozilla Firefox, specifically older ESR builds preceding 115.41 and 140.16, and Mozilla Thunderbird before version 140.16. The fix was applied in ESR 115.41, ESR 140.16, and Thunderbird 140.16, so any versions earlier than these are at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS score of < 1% indicates a very low exploitation probability. The issue is not listed in the CISA KEV catalog. Attack vector details are not specified in the advisory, implying that further analysis is needed to identify how an attacker might trigger the boundary error. The typical impact would be privilege escalation, potentially leading to broader system compromise if the attacker gains administrative rights.
OpenCVE Enrichment
Debian DLA
Debian DSA