CVE-2018-20817
high-risk
Published 2019-04-19
SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2.
Do I need to act?
~
3.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (6)
Call Of Duty\
Call Of Duty\
Call Of Duty\
Call Of Duty\
Call Of Duty\
Call Of Duty\
Affected Vendors
References (4)
Third Party Advisory
https://github.com/momo5502/cod-exploits/tree/master/steam-auth
Third Party Advisory
https://github.com/momo5502/cod-exploits/tree/master/steam-auth
51
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
6/34 · Minimal
Exposure
13/34 · Low