VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow
Cybersecurity Classified by Officially
Overview
Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitrary code on lobby members' machines through specially crafted data.
Description
Metal Gear Online 3 is an online 8 vs. 8 competitive shooter game that uses Steam Matchmaking to handle its multiplayer lobbies and matches. As detailed in CVE‑2026‑19874, version 1.1.2.8 of Metal Gear Online 3 (Steam AppID 287700) contains an input‑validation vulnerability in the processing of Steam lobby metadata related to the player‑removal feature. The game tracks a lobby field (kick_num) indicating the number of players designated for removal, along with corresponding Steam ID entries of each kicked player (kicked_id_%i). When joining a lobby, the player's client parses these fields to check whether its own Steam ID is on the list, and if so, the player is prevented from joining the match.
The function responsible for parsing this lobby data does not validate the kick_num value against the size of the fixed‑length buffer allocated for kicked player identifiers. Supplying a kick_num value larger than the buffer capacity results in out‑of‑bounds writes into adjacent memory. The memory region immediately following this buffer contains internal Steamworks callback handler structures that store function pointers and callback arguments for processing lobby data changes, messages, and other related events. By manipulating the overflow, an attacker can corrupt these handler structures and redirect callback execution, resulting in control‑flow hijacking on affected client systems. The vulnerability can be triggered automatically when a client joins a lobby controlled by an attacker.
Impact
This is an extract. The publication continues at the source.
Read the original at the source: https://kb.cert.org/vuls/id/728712
Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- CERT Coordination Center — imported from official source
- Official source
- https://www.kb.cert.org/vuls/atomfeed/ ATOM
- Imported
- September 15, 2026 20:57
- Versions
- 2 recorded
- Identity
https://kb.cert.org/vuls/id/728712