Impact
The Enterprise Policies component in Mozilla’s products contains a flaw that allows an attacker to manipulate or replace policy files to gain elevated privileges normally reserved for trusted users. This reflects a privilege management weakness and is categorized as CWE-266 and CWE-269. An attacker who is able to write to policy directories could execute actions with higher privileges, potentially compromising the entire system.
Affected Systems
Mozilla Firefox versions prior to 156 and Firefox ESR 153.3 are affected; similarly, Mozilla Thunderbird versions prior to 156 and Thunderbird ESR 153.3 are vulnerable. All builds in these ranges are susceptible unless the specified updates are installed.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of < 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating limited known active exploitation. Based on the description, the likely attack vector is inferred as tampering with Enterprise Policies files or exploiting a local scenario where policy files can be written by a non‑privileged process.
OpenCVE Enrichment