Impact
This vulnerability involves the Widget: Win32 component in Mozilla Firefox and Thunderbird. It allows an attacker to bypass the default security mitigations that this component provides. Such a bypass could enable malicious actions that would otherwise be suppressed by the component’s protection mechanisms.
Affected Systems
Mozilla Firefox versions older than 156, Firefox ESR 153.3, and Mozilla Thunderbird older than 156 were affected. The security fixes were delivered as part of the 156 releases for both Firefox and Thunderbird.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. The EPSS score of less than 1% indicates a low probability of exploitation at the time. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Based on the description, the likely attack vector is a malicious payload processed by the Widget: Win32 component, although specific environmental or prerequisites are not detailed.
OpenCVE Enrichment