Impact
A buffer overrun in the Memory component (CWE‑119) allows an attacker who can supply corrupt data to corrupt the process’s memory. The corruption can be used to elevate privileges within the browser or mail client or to execute arbitrary code, potentially leading to full system compromise.
Affected Systems
All Mozilla Firefox releases prior to version 156, and the Firefox ESR release before 153.3, as well as all versions of Thunderbird earlier than 156 are vulnerable. The vulnerability was resolved in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. While the description does not specify the attack surface, the nature of the memory corruption suggests it can be triggered by malicious input to the component, which may be delivered remotely (e.g., through a crafted web page or email) or locally by executing untrusted code. The likely attack vector is therefore either remote or local, depending on how the vulnerable input can be reached. The risk is elevated because the fault permits privilege escalation and potential arbitrary code execution.
OpenCVE Enrichment