6
CVSSv2

CVE-2008-1127

Published: 03/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered when the game character is killed.

Vulnerable Product Search on Vulmon Subscribe to Product

crytek crysis 1.1.1.5879

Exploits

The Crysis engine passes along internal debug strings through the game One of them is passed to vsprintf() in the crt lib: 30503263 8D8C24 10100000 LEA ECX,DWORD PTR SS:[ESP+1010] 3050326A 51 PUSH ECX 3050326B 50 PUSH EAX 3050326C 8D5424 08 LEA EDX,DWORD PTR SS:[ESP+8] 30503270 52 PUSH E ...