Impact
The vulnerability is caused by incorrect boundary checks in the Widget: Win32 component, allowing an attacker to escape the sandbox reserved for that component. The weakness manifests as a buffer overflow (CWE‑119) and an improper handling of input boundaries (CWE‑501), creating a path for code or data to reach outside the intended memory region.
Affected Systems
Mozilla Firefox versions prior to 156 and Firefox ESR 153.3, as well as Mozilla Thunderbird versions prior to 156 and Thunderbird ESR 153.3, are susceptible to this flaw.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, whereas the EPSS score of less than 1% and the absence of the issue from CISA’s KEV catalogue point to a low probability of exploitation at present. The likely attack vector involves an untrusted input that triggers the faulty boundary conditions within the Widget: Win32 component; however, no active exploitation has been observed.
OpenCVE Enrichment