ZeroHour
Vendor

Konami

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow

CERT/CC details CVE-2026-19874, a heap overflow in Metal Gear Online 3 letting match hosts execute code on lobby members' machines.

VU#728712 describes a heap-based buffer overflow in Konami's Metal Gear Online 3, tracked as CVE-2026-19874, affecting version 1.1.2.8 (Steam AppID 287700). The input-validation flaw lies in processing Steam lobby metadata tied to the player-removal feature, letting a match host trigger remote code execution on lobby members' machines via specially crafted data. The game is an 8v8 competitive shooter using Steam Matchmaking for lobbies.

Related CVEs

  • Heap-Based Buffer Overflow in Konami Metal Gear Online 3 Enables Code Execution
    CVE-2026-19874 is a critical heap-based buffer overflow (CWE-122) in the lobby-data handling of Konami's Metal Gear Online 3: the code trusts the "kick_num" field for the count of kicked-player identifiers (supplied as "kicked_id_%i" keys) without validating it against the 16-entry buffer sized for the game's maximum match size. An attacker who can supply crafted lobby data, such as a lobby host or participant, can set "kick_num" above 16, causing the parser to write past the end of the kicked-ID buffer and into adjacent memory containing Steam callback handler structures, overwriting function pointers and callback arguments. This can lead to control-flow hijacking and potentially arbitrary code execution within the game process; the CVSS 9.1 score reflects network reachability with no privileges or user interaction required. Any player running the affected title who joins or hosts lobbies with untrusted peers is exposed (the described code path touches Steam callback structures, indicating the Steam-integrated client); no fixed version information is included in the available data. There is currently no public proof-of-concept, no known in-the-wild exploitation, and the issue is not in CISA's KEV; EPSS estimates a 0.7% probability of exploitation within 30 days (52nd percentile).
    · Konami Metal Gear Online 3niche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.