vendor:
Unreal Tournament 2004
by:
stinko
10
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Unreal Tournament 2004
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2004-0608
CPE: a:unreal_tournament_2004:unreal_tournament_2004
Platforms Tested: Windows
2004
Unreal Tournament 2004 “secure” Overflow (Win32)
This is an exploit for the GameSpy secure query in the Unreal Engine. This exploit only requires one UDP packet, which can be both spoofed and sent to a broadcast address. Usually, the GameSpy query server listens on port 7787, but you can manually specify the port as well. The RunServer.sh script will automatically restart the server upon a crash, giving us the ability to bruteforce the service and exploit it multiple times.
Mitigation:
Update to a patched version of Unreal Tournament 2004. Disable the GameSpy query server if not needed.