Impact
This vulnerability arises from incorrect boundary conditions in the Widget: Win32 component, allowing an attacker to escape the browser sandbox and execute code with elevated privileges. The flaw can compromise the affected application and potentially the underlying host system if the sandbox protection is bypassed. It is an instance of improper boundary validation that directly undermines confinement guarantees.
Affected Systems
All Mozilla Firefox versions prior to 156 and ESR 153.3, as well as Thunderbird builds before 156, are affected by the Widget: Win32 component flaw. The issue exists in both mainstream and extended support releases of the browsers.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV. While there is no publicly confirmed exploitation, the nature of the bug—sandbox escape—suggests a potential impact if exploited. The CVSS score of 9.6 indicates a high severity for this sandbox escape, underscoring the need for timely remediation. Patch availability in newer releases indicates that the risk can be mitigated by updating the software. Absence of a known workaround means that the primary defense is upgrading to a fixed version.
OpenCVE Enrichment