Impact
This vulnerability involves a bypass of security mitigations enforced by Mozilla’s Enterprise Policies component. It arises from a flaw in the policy enforcement logic that allows an attacker to override or eliminate normally protected settings or actions. The weakness corresponds to improper access control, as identified by CWE‑1220 and CWE‑693, and could lead to unauthorized configuration changes, privilege elevation within the application, or compromise of data integrity and confidentiality.
Affected Systems
The affected products are Mozilla Firefox and Mozilla Thunderbird. Versions before the security fixes—Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3—are vulnerable. The issue is present in both the standard and ESR release lines, meaning users on either branch must upgrade.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed active exploits. Based on the description, the attack path most plausibly requires an attacker to be able to influence the enterprise policy engine—most likely through local user interaction or via a compromised account with policy configuration capabilities—rather than through a remote network vector.
OpenCVE Enrichment