Malformed .BSP Access Violation in CS:GO can lead to Remote Code Execution
Critical
V
Valve
Submitted None
Actions:
Reported by
chippy
Vulnerability Details
Technical details and impact analysis
A malformed .BSP can trigger an Access Violation on CS:GO that can lead to arbitrary code execution on a remote computer. I have attached a copy of the malformed .BSP which reliably triggers an Access Violation on CS:GO.
## Impact
An attacker hosting a malicious server could compromise a remote client by having them download a custom map, triggering remote code execution on the victim's computer.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Classic Buffer Overflow