Deepin Linux's default document reader deepin-reader software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.
CVE-2023-50254
This high-severity CVE scores 7.8 under NVD CVSS v3. EPSS exploit probability: 2.1%, top 20% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.8
- EG Score
- 7.8(medium)
- EG Risk
- —
- EPSS
- 79.9%
- KEV
- Not listed
Published
December 22, 2023
Last Modified
June 17, 2026
References (6)
- security-advisories@githubhttps://github.com/linuxdeepin/deepin-reader/commit/4db7a079fb7bd77257b1b9208a7ab26aade8fe04
- security-advisories@githubhttps://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c3164489a89e06420c6
- security-advisories@githubhttps://github.com/linuxdeepin/developer-center/security/advisories/GHSA-q9jr-726g-9495
- af854a3a-2127-422b-91ae-364da2661108https://github.com/linuxdeepin/deepin-reader/commit/4db7a079fb7bd77257b1b9208a7ab26aade8fe04
- af854a3a-2127-422b-91ae-364da2661108https://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c3164489a89e06420c6
- af854a3a-2127-422b-91ae-364da2661108https://github.com/linuxdeepin/developer-center/security/advisories/GHSA-q9jr-726g-9495
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCfebinrev/deepin-linux_reader_RCE-exploitFirst seen Dec 22, 2023
CVE-2023-50254: PoC Exploit for Deepin-reader RCE that affects unpatched Deepin Linux Desktops. Deepin Linux's default document reader "deepin-reader" software suffers from a serious vulnerability due to a design flaw that leads to Remote Command Execution via crafted docx document.
Open source ↗
Frequently asked(5)
What is CVE-2023-50254?
When was CVE-2023-50254 disclosed?
Is CVE-2023-50254 actively exploited?
What is the CVSS score of CVE-2023-50254?
How do I remediate CVE-2023-50254?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2023-50254
Is Your Infrastructure Affected by CVE-2023-50254?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.