cbcvebase.
CVE-2023-26314
published 2023-02-22

CVE-2023-26314: The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with…

PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.98%
58.6th percentile
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianmono< mono 6.8.0.105+dfsg-3.3 (bookworm)mono 6.8.0.105+dfsg-3.3 (bookworm)
mono-projectmono
mono-projectmono
monomono>= 0 < 6.8.0.105+dfsg-3.3~deb11u16.8.0.105+dfsg-3.3~deb11u1
monomono>= 0 < 6.8.0.105+dfsg-3.36.8.0.105+dfsg-3.3
monomono>= 0 < 6.8.0.105+dfsg-3.36.8.0.105+dfsg-3.3
monomono>= 0 < 6.8.0.105+dfsg-3.36.8.0.105+dfsg-3.3

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.