CVE Feed

    Dashboard / CVE / CVE-2023-42800

    CVE-2023-42800

    Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client, or achieve remote code execution (RCE) on the client (with insufficient exploit mitigations or if mitigations can be bypassed). The bug was addressed in commit 24750d4b748fefa03d09fcfd6d45056faca354e0.

    Published:Dec 14, 2023
    Last Modified:Nov 27, 2024
    EPS:Dec 14, 2023
    EPSS Score:0.00649
    CVSS Score:8.8

    Affected Products

    Vendor
    Moonlight-stream
    Product
    Moonlight
    Vendor
    Moonlight-stream
    Product
    Moonlight-common-c
    Vendor
    Moonlight-stream
    Product
    Moonlight Embedded
    Vendor
    Moonlight-stream
    Product
    Moonlight Switch
    Vendor
    Moonlight-stream
    Product
    Moonlight Tv
    Vendor
    Moonlight-stream
    Product
    Moonlight Vita
    Vendor
    Moonlight-stream
    Product
    Moonlight Xbox

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High