vendor:
Crysis Engine
by:
ATOM
7.5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: Crysis Engine
Affected Version From: All versions of Crysis engine
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:crytek:crysis_engine
Platforms Tested: Windows
2008
Crysis Engine Format String Vulnerability
The Crysis engine passes along internal debug strings through the game, and one of them is passed to the vsprintf() function in the crt lib. This vulnerability can be exploited by sending a specially crafted format string as input, which can lead to remote code execution or denial of service.
Mitigation:
Apply patches released by the vendor or upgrade to a newer version of the game/engine.