PT-2004-2704 · Epic Games · Unreal Engine
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-1805
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Unreal Engine version 436
Description
The issue is related to a format string vulnerability in games that utilize the Epic Games Unreal Engine. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in a crash, and potentially execute arbitrary code. The exploitation is achieved through the use of format string specifiers in class names.
Recommendations
For Unreal Engine version 436, consider applying patches or updates that address format string vulnerabilities, specifically focusing on the proper handling of class names to prevent arbitrary code execution and denial of service attacks. As a temporary workaround, restrict the use of format string specifiers in class names until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Unreal Engine