CVE-2022-47949
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 22.26% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- nintendo/animal crossing\ · nintendo/arms · nintendo/mario kart 7 · nintendo/mario kart 8 · nintendo/splatoon · nintendo/splatoon 2 · nintendo/splatoon 3 · nintendo/super mario maker 2 · nintendo/switch sports
- Source
- cve@mitre.org
References
- https://github.com/PabloMK7/ENLBufferPwnExploit, Third Party Advisory
- https://github.com/PabloMK7/ENLBufferPwnExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.