Impact
The vulnerability resides in the Crash Reporting subsystem of Mozilla Firefox and Thunderbird. A crafted crash scenario can cause the component to grant privileged permissions to a local user, effectively allowing them to perform actions that normally require higher privileges. This misuse of the crash handling mechanism matches the pattern identified as a privilege‑escalation flaw.
Affected Systems
Versions of Firefox up to 155 and Firefox ESR below 153.3 are susceptible, as are Thunderbird builds older than 156 and Thunderbird ESR versions below 153.3. Users running any vulnerable release retain the risk until an update is applied.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA's KEV catalogue, indicating no known large‑scale attacks. Exploitation appears local: an attacker must trigger the Crash Reporting component, typically by causing a controlled crash or submitting a malicious crash report, which then permits the escalation of privileges within the application context. The absence of a publicly available exploit path does not negate the risk, particularly for users unable to promptly update their software.
OpenCVE Enrichment