Vulnerability Description
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Valvesoftware | Dota 2 | <= 2020-02-17 |
Related Weaknesses (CWE)
References
- https://github.com/bi7s/CVE/blob/master/CVE-2020-9005/README.mdExploitThird Party Advisory
- https://github.com/bi7s/CVE/blob/master/CVE-2020-9005/README.mdExploitThird Party Advisory
FAQ
What is CVE-2020-9005?
CVE-2020-9005 is a vulnerability with a CVSS score of 7.8 (HIGH). meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this s...
How severe is CVE-2020-9005?
CVE-2020-9005 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9005?
Check the references section above for vendor advisories and patch information. Affected products include: Valvesoftware Dota 2.