CVE-2020-7949 is a high-severity vulnerability affecting Valve Dota 2 versions prior to 7.23f, specifically within the schemasystem.dll. It allows remote attackers to achieve code execution or denial of service by creating a malicious gaming server and inviting a victim, exploiting a crafted map during a GetValue call. The vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and leading to high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, a Proof-of-Concept for denial of service is publicly available on ExploitDB, though there's no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.23fCPE matchmatch criteria | cpe:2.3:a:valvesoftware:dota_2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.