// For flags

CVE-2019-15943

Counter-Strike Global Offensive 1.37.1.1 - 'vphysics.dll' Denial of Service (PoC)

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a memset call.

La biblioteca vphysics.dll en Counter-Strike: Global Offensive versiones anteriores a 1.37.1.1, permite a atacantes remotos alcanzar la ejecución de código o la denegación de servicio mediante la creación de un servidor de juegos e invitar a una víctima a este servidor, porque un mapa diseñado es manejado inapropiadamente durante una llamada de memset.

Counter-Strike Global Offensive (vphysics.dll) versions prior to 1.37.1.1 allow remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, using a crafted map that causes memory corruption.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-09-05 CVE Reserved
  • 2019-09-18 First Exploit
  • 2019-09-19 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-09-12 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Valvesoftware
Search vendor "Valvesoftware"
Counter-strike: Global Offensive
Search vendor "Valvesoftware" for product "Counter-strike: Global Offensive"
< 1.37.1.1
Search vendor "Valvesoftware" for product "Counter-strike: Global Offensive" and version " < 1.37.1.1"
-
Affected