CVE-2023-35373Improper Verification of Cryptographic Signature in Microsoft Mono 6.12.0

Severity
5.3MEDIUMNVD
EPSS
0.5%
top 32.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11

Description

Mono Authenticode Validation Spoofing Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

NVDmicrosoft/mono6.12.06.12.0.200
CVEListV5microsoft/mono_6.12.06.12.06.12.0.200

Patches

🔴Vulnerability Details

2
GHSA
GHSA-34j3-g2w8-qhjx: Mono Authenticode Validation Spoofing Vulnerability2023-07-11
CVEList
Mono Authenticode Validation Spoofing Vulnerability2023-07-11

📋Vendor Advisories

1
Microsoft
Mono Authenticode Validation Spoofing Vulnerability2023-07-11
CVE-2023-35373 — Microsoft Mono 6.12.0 vulnerability | cvebase