Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1999023

27
FAUCET Score

CVE-2018-1999023 is a high-severity code injection vulnerability affecting The Battle for Wesnoth versions 1.7.0 through 1.14.3. This flaw allows for arbitrary code execution outside the game's sandbox through specially crafted saved games, networked games, replays, or player content. With a CVSS score of 8.8, the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.7.0, <= 1.14.3CPE matchmatch criteria
cpe:2.3:a:wesnoth:the_battle_for_wesnoth:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.8HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.72%
Probability of exploitation in next 30 days
EPSS Percentile
75.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0172 is in the 74th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: 16939-17084Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: 16939-16817Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: 19856-17084Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: azl3 ceph 18.2.1-1 on Azure Linux 3.0Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: azl3 ceph 16.2.10-3 on Azure Linux 3.0Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 18.2.1-1

Vendor Advisories (2)

microsoft2024-Jun/CVE-2018-1999023

CVE-2018-1999023

Jun 11, 2024
microsoft2018-Jul/CVE-2018-1999023Important

The Battle for Wesnoth Project contains a Code Injection that can result in code execution outside the sandbox

Jul 10, 2018

References

gist.github.com / shikadiqueen/45951ddc981cf8e0d9a74e4b30400380
PatchThird Party Advisory