CVE-2004-0608 describes a critical remote code execution vulnerability affecting numerous games built on the Unreal Engine, including DeusEx, Unreal Tournament, and Postal 2. An unauthenticated remote attacker can exploit this by sending a specially crafted UDP packet containing a long value in a secure query, leading to memory corruption and arbitrary code execution. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with no authentication required, allowing for complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV, Metasploit modules exist for both Linux and Windows, indicating readily available exploit code, though there is no evidence of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
390.0CPE matchmatch criteria | cpe:2.3:a:arush:devastation:390.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:dreamforge:tnn_outdoors_pro_hunter:*:*:*:*:*:*:*:* | ||
226fCPE matchmatch criteria | cpe:2.3:a:epic_games:unreal_engine:226f:*:*:*:*:*:*:* | ||
433CPE matchmatch criteria | cpe:2.3:a:epic_games:unreal_engine:433:*:*:*:*:*:*:* | ||
436CPE matchmatch criteria | cpe:2.3:a:epic_games:unreal_engine:436:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.