Sceawere

Vulnerability Detail

CVE-2026-74965UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Firefox Shell Integration Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
Mozilla
Product
Firefox
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-18T13:17:33.813Z",
  "pubdate": "2026-08-18T13:17:33.813Z",
  "executiveSummary": "A privilege escalation vulnerability exists within the Shell Integration component of Mozilla Firefox. The security flaw allows unauthorized privilege elevation within the affected operating system context through improper handling of shell integration routines.\nThe vulnerability directly impacts Firefox, Firefox ESR 140.14, and Firefox ESR 153.1. Successful exploitation of this vulnerability can lead to unauthorized privilege escalation, potentially granting an attacker elevated system access depending on the execution context of the underlying component.\nThe risk implications are severe, as local privilege escalation typically compromises the integrity and confidentiality of the host system. The attacker capabilities involve leveraging the flawed Shell Integration component to execute privileged operations or access restricted resources.\nSpecific exploitation requirements and attacker capabilities are constrained by the local execution context necessary to interact with the vulnerable Shell Integration component. Organizations and users must apply the provided vendor patches to eliminate the underlying flaw and secure the application environment.",
  "technicalDetails": "The vulnerability resides specifically within the Shell Integration component of the affected software. The root cause stems from insecure design, insufficient input validation, or improper handling of system commands and integration parameters within the vulnerable component.\nThe affected versions include Firefox (prior to version 154), Firefox ESR (prior to version 140.14), and Firefox ESR (prior to version 153.1). The flaw enables a local threat actor to manipulate execution flows or abuse exposed interfaces within the Shell Integration architecture to achieve unauthorized privilege escalation.\nThe attack flow typically begins with an adversary obtaining local execution capabilities or interacting with the vulnerable application instance. The attacker crafts specific inputs or triggers specific routines within the Shell Integration component that fail to properly sanitize or validate execution parameters. Because the component executes with elevated privileges or interacts with privileged OS subsystems, the improper handling results in the execution of unintended commands or the unauthorized elevation of privileges.\nAuthentication and privilege requirements depend on the local execution constraints of the target system, though local access to the application environment or host is generally required to interact with the Shell Integration component. Network exposure is not a primary vector since the vulnerability is localized to the internal inter-component communication and OS integration layers.\nPost-exploitation impact involves the unauthorized escalation of privileges, potentially allowing the execution of arbitrary code within a higher integrity context, bypassing security controls, and compromising the overall security posture of the host operating system."
}
CVE-2026-74965: Firefox Shell Integration Privilege Escalation (HIGH Severity, CVSS: 8.8) - Sceawere