First published: Mon Jan 27 2020(Updated: )
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dota 2 | <7.23f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7949 is a vulnerability in Valve Dota 2 before version 7.23f that allows remote attackers to achieve code execution or denial of service.
CVE-2020-7949 can be exploited by creating a gaming server and inviting a victim to join, where a crafted map is mishandled during a GetValue call.
The severity of CVE-2020-7949 is high, with a CVSS score of 7.8.
Valve Dota 2 before version 7.23f is affected by CVE-2020-7949.
Yes, updating Valve Dota 2 to version 7.23f or newer will fix the vulnerability.