CyberSec.Space Logo
Back to CVE Browser

CVE-2018-20817

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0720%
EPSS Percentile44.06th
PublishedApr 19, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2.

Affected Platforms (CPE)

πŸ“¦
Activision

Call Of Duty\

= _advanced_warfare
πŸ“¦
Activision

Call Of Duty\

= _black_ops_1
πŸ“¦
Activision

Call Of Duty\

= _blacks_ops_2
πŸ“¦
Activision

Call Of Duty\

= _ghosts
πŸ“¦
Activision

Call Of Duty\

= _modern_warfare_2
πŸ“¦
Activision

Call Of Duty\

= _modern_warfare_3

References & Advisories

Related Vulnerabilities