CVE-2020-7949
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.17% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- valvesoftware/dota 2
- Source
- cve@mitre.org
References
- https://github.com/bi7s/CVE/tree/master/CVE-2020-7949Third Party Advisory
- https://github.com/bi7s/CVE/tree/master/CVE-2020-7949Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.