CVE-2023-42799
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client, or achieve remote code execution (RCE) on the client (with insufficient exploit mitigations or if mitigations can be bypassed). The bug was addressed in commit 02b7742f4d19631024bd766bd2bb76715780004e.
Published:Dec 14, 2023
Last Modified:Nov 21, 2024
EPS:Dec 14, 2023
EPSS Score:0.00533
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Moonlight-stream
Product
Moonlight
Moonlight-stream
Moonlight
Vendor
Moonlight-stream
Product
Moonlight-common-c
Moonlight-stream
Moonlight-common-c
Vendor
Moonlight-stream
Product
Moonlight Embedded
Moonlight-stream
Moonlight Embedded
Vendor
Moonlight-stream
Product
Moonlight Switch
Moonlight-stream
Moonlight Switch
Vendor
Moonlight-stream
Product
Moonlight Tv
Moonlight-stream
Moonlight Tv
Vendor
Moonlight-stream
Product
Moonlight Vita
Moonlight-stream
Moonlight Vita
Vendor
Moonlight-stream
Product
Moonlight Xbox
Moonlight-stream
Moonlight Xbox
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
