First published: Mon Feb 17 2020(Updated: )
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dota 2 | <=2020-02-17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9005 is a vulnerability in meshsystem.dll in Valve Dota 2 that allows remote attackers to achieve code execution or denial of service.
CVE-2020-9005 works by creating a gaming server with a crafted map in Valve Dota 2 and inviting a victim to this server, where a mishandled GetValue call can be exploited.
The severity of CVE-2020-9005 is high with a severity value of 7.8.
To fix CVE-2020-9005, users should update to the latest version of Valve Dota 2 and ensure they are running the most recent security patches.
More information about CVE-2020-9005 can be found at the following link: [GitHub - CVE-2020-9005](https://github.com/bi7s/CVE/blob/master/CVE-2020-9005/README.md)