CVE-2023-42799
Last modified
CVE-2023-42799 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client, or achieve remote code execution (RCE) on the client (with insufficient exploit mitigations or if mitigations can be bypassed). The bug was addressed in commit 02b7742f4d19631024bd766bd2bb76715780004e.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moonlight-Stream | Moonlight-Common-C | >= 2022-11-04, < 2023-10-06 |
| Moonlight-Stream | Moonlight | >= 8.4.0, <= 8.5.0 |
| Moonlight-Stream | Moonlight | >= 10.10, <= 11.0 |
| Moonlight-Stream | Moonlight | 0.10.22 |
| Moonlight-Stream | Moonlight Embedded | 2.6.0 |
| Moonlight-Stream | Moonlight Xbox | >= 1.12.0, <= 1.14.40 |
| Moonlight-Stream | Moonlight Tv | >= 1.5.4, <= 1.5.27 |
| Moonlight-Stream | Moonlight Switch | >= 0.13, <= 0.13.3 |
| Moonlight-Stream | Moonlight Vita | >= 0.9.2, <= 0.9.3 |
References
- https://github.com/moonlight-stream/moonlight-common-c/security/advisories/GHSA-r8cf-45f4-vf8mExploit, Third Party Advisory
- https://github.com/moonlight-stream/moonlight-common-c/security/advisories/GHSA-r8cf-45f4-vf8mExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-42799?
How severe is CVE-2023-42799?
How do I fix CVE-2023-42799?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-42793In JetBrains TeamCity before 2023.05.4 authentication bypass…9.8
- CVE-2023-42794Incomplete Cleanup vulnerability in Apache Tomcat. The inte…5.9
- CVE-2023-42795Incomplete Cleanup vulnerability in Apache Tomcat.When recyc…5.3
- CVE-2023-42796A vulnerability has been identified in CP-8031 MASTER MODULE…8.8
- CVE-2023-42797A vulnerability has been identified in CP-8031 MASTER MODULE…7.2
- CVE-2023-42798AutomataCI is a template git repository equipped with a nati…9.1
- CVE-2023-4280An unvalidated input in Silicon Labs TrustZone implementatio…9.8
- CVE-2023-42800Moonlight-common-c contains the core GameStream client code …8.8
- CVE-2023-42801Moonlight-common-c contains the core GameStream client code …7.6
- CVE-2023-42802GLPI is a free asset and IT management software package. Sta…9.8
- CVE-2023-42803BigBlueButton is an open-source virtual classroom. BigBlueBu…8.8
- CVE-2023-42804BigBlueButton is an open-source virtual classroom. BigBlueBu…5.3
Are you affected by CVE-2023-42799?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
