Loading HuntDB...

Malformed .BSP Access Violation in CS:GO can lead to Remote Code Execution

Critical
V
Valve
Submitted None
Reported by chippy

Vulnerability Details

Technical details and impact analysis

Classic Buffer Overflow
A malformed .BSP can trigger an Access Violation on CS:GO that can lead to arbitrary code execution on a remote computer. I have attached a copy of the malformed .BSP which reliably triggers an Access Violation on CS:GO. ## Impact An attacker hosting a malicious server could compromise a remote client by having them download a custom map, triggering remote code execution on the victim's computer.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Classic Buffer Overflow