vendor:
Counter-Strike Global Offensive
by:
bi7s
8.8
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Counter-Strike Global Offensive
Affected Version From: Counter-Strike Global Offensive (vphysics.dll) before 1.37.1.1
Affected Version To: Counter-Strike Global Offensive (vphysics.dll) 1.37.1.1
Patch Exists: YES
Related CWE: CVE-2019-15943
CPE: 2.3:a:valve:counter-strike_global_offensive
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
CVE-2019-15943
Counter-Strike Global Offensive (vphysics.dll) before 1.37.1.1 is vulnerable to a memory corruption vulnerability which can be exploited by creating a gaming server and inviting a victim to this server. An attacker can craft a malicious map using memory corruption and modify the class name value in the PoC for triggering this vulnerability. The offset for modifying the PoC is 0x115703. After copying the malicious map to the game directory, the attacker can start the game with the malicious map and exploit the vulnerability to achieve code execution or denial of service.
Mitigation:
Users should update their Counter-Strike Global Offensive (vphysics.dll) to version 1.37.1.1 or later to mitigate this vulnerability.