Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow

0
Critical
VulnerabilityCVE-2026-19874remotercecvecve-2026-19874cwe-122gcve
Published: 08/24/2026 (08/24/2026, 15:02:51 UTC)
Source: CERT/CC

Description

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches to a maximum of 16 players, and the corresponding buffer for storing kicked player IDs is sized accordingly. If "kick_num" exceeds this limit, the function continues writing the provided player IDs past the end of the intended buffer and into adjacent memory regions. These adjacent regions contain Steam callback handler structures responsible for processing lobby data updates, lobby messages, and other related events. By supplying an oversized "kick_num" value and appropriate "kicked_id_%i" fields, an attacker can overwrite fields within the callback handler structures, including function pointers and callback argument values. Successful exploitation may enable control-flow hijacking, potentially allowing arbitrary code execution within the game process.

Affected software

GitHub Actionsmore threats →ai
konami/metal-gear-online-3
pkg:github/konami/metal-gear-online-3
Affected versions
=1.1.2.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/24/2026, 15:04:56 UTC

Technical Analysis

Metal Gear Online 3 (Steam AppID 287700) version 1.1.2.8 has an input-validation vulnerability in the Steam lobby metadata processing for the player-removal feature. The kick_num field, indicating the number of players to be removed, is not validated against the fixed-length buffer size allocated for kicked player identifiers. An attacker controlling a lobby can supply a kick_num value larger than the buffer capacity, causing out-of-bounds writes that overwrite adjacent Steamworks callback handler structures containing function pointers. This enables control-flow hijacking and remote code execution on clients joining the lobby. The Metal Gear Online 3 binary includes Denuvo-protected RWX memory regions, allowing injected code execution at runtime. Host privileges can be reassigned during matches, enabling an attacker to compromise multiple clients via a single lobby. The vulnerability is addressed in version 1.1.2.9 of mgsvmgo.exe, which also increments server and lobby version numbers to block older vulnerable clients.

Potential Impact

Successful exploitation allows an attacker hosting a lobby to remotely execute arbitrary code on any client that joins, without requiring victim interaction beyond joining the lobby. The presence of RWX Denuvo-protected regions in the binary increases the severity by permitting runtime code injection. Additionally, host privileges can be reassigned during matches, enabling the attacker to spread the exploit to multiple players in an active session. This results in a high risk of widespread client compromise in multiplayer environments.

Mitigation Recommendations

A fix for this vulnerability is available in Metal Gear Online 3 version 1.1.2.9. This patch updates the executable mgsvmgo.exe and increments server and lobby version numbers to prevent vulnerable clients from connecting. Users and administrators should upgrade to version 1.1.2.9 or later to remediate this issue. No vendor advisory was released at the time of this report, but the patch is confirmed via SteamDB patch notes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.73,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/728712","fetched":true,"fetchedAt":"2026-08-24T15:04:45.527Z","wordCount":683}

Threat ID: 6a8c5d8dacd9273b49b32f76

Added to database: 08/24/2026, 15:04:45 UTC

Last enriched: 08/24/2026, 15:04:56 UTC

Last updated: 08/24/2026, 16:41:27 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses