Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-42801

21
FAUCET Score

CVE-2023-42801 is a buffer overflow vulnerability in Moonlight-common-c, affecting various Moonlight client applications. A malicious game streaming server could exploit this flaw to crash a Moonlight client, with potential for remote code execution (RCE) though mitigated by stack canaries in official builds. The vulnerability requires the client to be tricked into pairing with a malicious host, as man-in-the-middle attacks are prevented by public key pinning. With a CVSS score of 7.6 (High), the attack vector is network-based with low complexity, requiring user interaction, and primarily impacts availability, with some potential for confidentiality and integrity loss. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2016-10-05, < 2023-10-06CPE matchmatch criteria
cpe:2.3:a:moonlight-stream:moonlight-common-c:*:*:*:*:*:*:*:*
< 9.0.0CPE matchmatch criteria
cpe:2.3:a:moonlight-stream:moonlight:*:*:*:*:*:iphone_os:*:*
< 9.0.0CPE matchmatch criteria
cpe:2.3:a:moonlight-stream:moonlight:*:*:*:*:*:tvos:*:*
< 12.0CPE matchmatch criteria
cpe:2.3:a:moonlight-stream:moonlight:*:*:*:*:*:android:*:*
< 0.10.23CPE matchmatch criteria
cpe:2.3:a:moonlight-stream:moonlight:*:*:*:*:*:chrome:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 54th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / moonlight-stream/moonlight-common-c/blob/c1744de06938b5a5c8897a705be1bc6508dc7580/src/Misc.c
Exploit
github.com / moonlight-stream/moonlight-common-c/commit/b2497a3918a6d79808d9fd0c04734786e70d5954
Patch
github.com / moonlight-stream/moonlight-common-c/commit/f57bd745b4cbed577ea654fad4701bea4d38b44c
Patch
github.com / moonlight-stream/moonlight-common-c/security/advisories/GHSA-f3h8-j898-5h5v
ExploitThird Party Advisory