Lucene search

K
cveMitreCVE-2018-20817
HistoryApr 19, 2019 - 11:29 p.m.

CVE-2018-20817

2019-04-1923:29:00
CWE-119
mitre
web.nvd.nist.gov
37
27
cve-2018-20817
sv_steamauthclient
activision
infinity ward
call of duty
remote code execution
vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.011

Percentile

84.7%

SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2.

Affected configurations

Nvd
Node
activisioncall_of_duty\Match_advanced_warfare-
OR
activisioncall_of_duty\Match_black_ops_1-
OR
activisioncall_of_duty\Match_blacks_ops_2-
OR
activisioncall_of_duty\Match_ghosts-
OR
activisioncall_of_duty\Match_modern_warfare_2-
OR
activisioncall_of_duty\Match_modern_warfare_3-
VendorProductVersionCPE
activisioncall_of_duty\_advanced_warfarecpe:2.3:a:activision:call_of_duty\:_advanced_warfare:-:*:*:*:*:*:*:*
activisioncall_of_duty\_black_ops_1cpe:2.3:a:activision:call_of_duty\:_black_ops_1:-:*:*:*:*:*:*:*
activisioncall_of_duty\_blacks_ops_2cpe:2.3:a:activision:call_of_duty\:_blacks_ops_2:-:*:*:*:*:*:*:*
activisioncall_of_duty\_ghostscpe:2.3:a:activision:call_of_duty\:_ghosts:-:*:*:*:*:*:*:*
activisioncall_of_duty\_modern_warfare_2cpe:2.3:a:activision:call_of_duty\:_modern_warfare_2:-:*:*:*:*:*:*:*
activisioncall_of_duty\_modern_warfare_3cpe:2.3:a:activision:call_of_duty\:_modern_warfare_3:-:*:*:*:*:*:*:*

Social References

More

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.011

Percentile

84.7%

Related for CVE-2018-20817