A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.
History

Thu, 17 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 21:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.
Title Heroes of Might and Magic III .h3m Map File Buffer Overflow
Weaknesses CWE-121
CWE-20
CWE-94
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-07-16T21:08:33.123Z

Updated: 2025-07-17T19:39:42.701Z

Reserved: 2025-04-15T19:15:22.561Z

Link: CVE-2025-34124

cve-icon Vulnrichment

Updated: 2025-07-17T19:39:38.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-16T22:15:23.840

Modified: 2025-07-17T21:15:50.197

Link: CVE-2025-34124

cve-icon Redhat

No data.