Impact
This vulnerability is a bypass of core security mitigations in Mozilla’s Remote Settings Client. An attacker can supply crafted configuration data that the client accepts because of improper input validation, falling under CWE-807, and due to missing authorization controls, also corresponding to CWE-693. The flaw permits an adversary to change security settings, policies, or other configuration parameters that would normally be protected, thereby compromising the integrity of the browser or email client.
Affected Systems
All Mozilla Firefox and Thunderbird installations that are older than Firefox 156, Firefox ESR 153.3, Thunderbird 156, or Thunderbird 153.3 are vulnerable. Versions prior to these patch releases lack the documented fix.
Risk and Exploitability
The EPSS score of less than 1% indicates that, at present, exploitation attempts are expected to be low in frequency. The vulnerability is not listed in the CISA KEV catalog. However, because it allows an attacker to subvert fundamental security controls, the inherent risk remains high. Based on the description, it is inferred that an attacker could control a remote settings server or otherwise influence the data fed to the client; the Remote Settings Client would accept malicious configuration changes, potentially enabling further attacks such as credential theft or privilege escalation. The CVSS score of 9.1 places this issue in the critical severity range, underscoring its significant potential impact.
OpenCVE Enrichment