CVE-2023-26314

high
Published 2023-02-22 · Modified 2026-05-20
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-26314

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.debian.org/972146

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed6.8.0.105+dfsg-3.3
debian debianbullseyefixed6.8.0.105+dfsg-3.3~deb11u1
debian debianforkyfixed6.8.0.105+dfsg-3.3
debian debiansidfixed6.8.0.105+dfsg-3.3
debian debiantrixiefixed6.8.0.105+dfsg-3.3
debian debian10.0affected

Application impact

VendorProductVersionsFixed
mono-projectmono5.18.0.240\+dfsg-3
mono-projectmono6.8.0.105\+dfsg-3

References

Verify integrity in audit chain (admin only). AS-IS.