CVE-2008-3116
Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.55% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-134
- Affected
- hanghai/5th street · hanghai/high street 5 · hanghai/hot step
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/3982
- http://www.securityfocus.com/archive/1/493649/100/0/threaded
- http://www.securityfocus.com/bid/29928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43370
- http://securityreason.com/securityalert/3982
- http://www.securityfocus.com/archive/1/493649/100/0/threaded
- http://www.securityfocus.com/bid/29928
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43370
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.