vendor:
Dota 2
by:
Bogdan Kurinnoy (b.kurinnoy@gmail.com) (bi7s)
7.8
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Dota 2
Affected Version From: 7.23f
Affected Version To: 7.23f
Patch Exists: YES
Related CWE: CVE-2020-7949
CPE: a:valve:dota_2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 (x64)
2020
Dota 2 7.23f – Denial of Service (PoC)
Valve Dota 2 (schemasystem.dll) before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call. Attacker need invite a victim to play on attacker game server using specially crafted map or create custom game, then when initialize the game of the victim, the specially crafted map will be automatically downloaded and processed by the victim, which will lead to the possibility to exploit vulnerability. Also attacker can create custom map and upload it to Steam.
Mitigation:
Valve has released a patch to address this vulnerability.