PT-2004-2704 · Epic Games · Unreal Engine

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1805

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Unreal Engine version 436
Description The issue is related to a format string vulnerability in games that utilize the Epic Games Unreal Engine. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in a crash, and potentially execute arbitrary code. The exploitation is achieved through the use of format string specifiers in class names.
Recommendations For Unreal Engine version 436, consider applying patches or updates that address format string vulnerabilities, specifically focusing on the proper handling of class names to prevent arbitrary code execution and denial of service attacks. As a temporary workaround, restrict the use of format string specifiers in class names until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1805

Affected Products

Unreal Engine