9.8
CVSSv3

CVE-2018-20817

Published: 19/04/2019 Updated: 22/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games prior to 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

activision call of duty\\ _modern_warfare_2

activision call of duty\\ _modern_warfare_3

activision call of duty\\ _ghosts

activision call of duty\\ _black_ops_1

activision call of duty\\ _advanced_warfare

activision call of duty\\ _blacks_ops_2

Github Repositories

☠️ Call of Duty - Vulnerabilities and proof-of-concepts

COD Exploits This repository documents several vulnerabilities in Call of Duty and provides proof-of-concepts for each of them Vulnerabilities Name CVE-ID Steam-Auth CVE-2018-20817 Huffman CVE-2018-10718 Disclaimer This software has been created purely for the purposes of academic research It is not intended to be used to attack other systems Project maintainers

☠️ Call of Duty - Vulnerabilities and proof-of-concepts

COD Exploits This repository documents several vulnerabilities in Call of Duty and provides proof-of-concepts for each of them Vulnerabilities Name CVE-ID Steam-Auth CVE-2018-20817 Huffman CVE-2018-10718 Disclaimer This software has been created purely for the purposes of academic research It is not intended to be used to attack other systems Project maintainers

CoD SteamAuth RCE This repository contains the Proof-of-Concept for the SteamAuth vulnerability in various Call of Duty games CVE-ID: CVE-2018-20817 Disclaimer This software has been created purely for the purposes of academic research It is not intended to be used to attack other systems Project maintainers are not responsible or liable for misuse of the software Use respo