Impact
The vulnerability is caused by incorrect boundary checks in the Widget: Win32 component, which can result in a sandbox escape. This flaw would allow an attacker to execute code with the privileges of the offending application. Based on the description, the primary risk is the ability to run arbitrary code in the context of Firefox or Thunderbird, potentially compromising the user’s data or system.
Affected Systems
Mozilla products – Firefox versions earlier than 156 and ESR 153.3, and Thunderbird versions earlier than 156 are affected. The security advisory states that the issue was fixed in those releases.
Risk and Exploitability
The EPSS score of <1% indicates a very low likelihood of exploitation, and the CVSS score of 8.8 places the vulnerability in the high severity range. Although the flaw is not listed in CISA’s KEV catalog, the potential impact of sandbox escape is significant. The likely attack vector, inferred from the description, involves an attacker supplying a malicious Widget: Win32 file to the application, which is realistic in environments where user‑supplied widgets are allowed. Thus, while exploitation probability remains low, the impact warrants precautionary action.
OpenCVE Enrichment