VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches to a maximum of 16 players, and the corresponding buffer for storing kicked player IDs is sized accordingly. If "kick_num" exceeds this limit, the function continues writing the provided player IDs past the end of the intended buffer and into adjacent memory regions. These adjacent regions contain Steam callback handler structures responsible for processing lobby data updates, lobby messages, and other related events. By supplying an oversized "kick_num" value and appropriate "kicked_id_%i" fields, an attacker can overwrite fields within the callback handler structures, including function pointers and callback argument values. Successful exploitation may enable control-flow hijacking, potentially allowing arbitrary code execution within the game process.
AI Analysis
Technical Summary
Metal Gear Online 3 (Steam AppID 287700) version 1.1.2.8 has an input-validation vulnerability in the Steam lobby metadata processing for the player-removal feature. The kick_num field, indicating the number of players to be removed, is not validated against the fixed-length buffer size allocated for kicked player identifiers. An attacker controlling a lobby can supply a kick_num value larger than the buffer capacity, causing out-of-bounds writes that overwrite adjacent Steamworks callback handler structures containing function pointers. This enables control-flow hijacking and remote code execution on clients joining the lobby. The Metal Gear Online 3 binary includes Denuvo-protected RWX memory regions, allowing injected code execution at runtime. Host privileges can be reassigned during matches, enabling an attacker to compromise multiple clients via a single lobby. The vulnerability is addressed in version 1.1.2.9 of mgsvmgo.exe, which also increments server and lobby version numbers to block older vulnerable clients.
Potential Impact
Successful exploitation allows an attacker hosting a lobby to remotely execute arbitrary code on any client that joins, without requiring victim interaction beyond joining the lobby. The presence of RWX Denuvo-protected regions in the binary increases the severity by permitting runtime code injection. Additionally, host privileges can be reassigned during matches, enabling the attacker to spread the exploit to multiple players in an active session. This results in a high risk of widespread client compromise in multiplayer environments.
Mitigation Recommendations
A fix for this vulnerability is available in Metal Gear Online 3 version 1.1.2.9. This patch updates the executable mgsvmgo.exe and increments server and lobby version numbers to prevent vulnerable clients from connecting. Users and administrators should upgrade to version 1.1.2.9 or later to remediate this issue. No vendor advisory was released at the time of this report, but the patch is confirmed via SteamDB patch notes.
VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow
Description
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches to a maximum of 16 players, and the corresponding buffer for storing kicked player IDs is sized accordingly. If "kick_num" exceeds this limit, the function continues writing the provided player IDs past the end of the intended buffer and into adjacent memory regions. These adjacent regions contain Steam callback handler structures responsible for processing lobby data updates, lobby messages, and other related events. By supplying an oversized "kick_num" value and appropriate "kicked_id_%i" fields, an attacker can overwrite fields within the callback handler structures, including function pointers and callback argument values. Successful exploitation may enable control-flow hijacking, potentially allowing arbitrary code execution within the game process.
Affected software
pkg:github/konami/metal-gear-online-3Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Metal Gear Online 3 (Steam AppID 287700) version 1.1.2.8 has an input-validation vulnerability in the Steam lobby metadata processing for the player-removal feature. The kick_num field, indicating the number of players to be removed, is not validated against the fixed-length buffer size allocated for kicked player identifiers. An attacker controlling a lobby can supply a kick_num value larger than the buffer capacity, causing out-of-bounds writes that overwrite adjacent Steamworks callback handler structures containing function pointers. This enables control-flow hijacking and remote code execution on clients joining the lobby. The Metal Gear Online 3 binary includes Denuvo-protected RWX memory regions, allowing injected code execution at runtime. Host privileges can be reassigned during matches, enabling an attacker to compromise multiple clients via a single lobby. The vulnerability is addressed in version 1.1.2.9 of mgsvmgo.exe, which also increments server and lobby version numbers to block older vulnerable clients.
Potential Impact
Successful exploitation allows an attacker hosting a lobby to remotely execute arbitrary code on any client that joins, without requiring victim interaction beyond joining the lobby. The presence of RWX Denuvo-protected regions in the binary increases the severity by permitting runtime code injection. Additionally, host privileges can be reassigned during matches, enabling the attacker to spread the exploit to multiple players in an active session. This results in a high risk of widespread client compromise in multiplayer environments.
Mitigation Recommendations
A fix for this vulnerability is available in Metal Gear Online 3 version 1.1.2.9. This patch updates the executable mgsvmgo.exe and increments server and lobby version numbers to prevent vulnerable clients from connecting. Users and administrators should upgrade to version 1.1.2.9 or later to remediate this issue. No vendor advisory was released at the time of this report, but the patch is confirmed via SteamDB patch notes.
Technical Details
- Classification
- {"confidence":0.73,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/728712","fetched":true,"fetchedAt":"2026-08-24T15:04:45.527Z","wordCount":683}
Threat ID: 6a8c5d8dacd9273b49b32f76
Added to database: 08/24/2026, 15:04:45 UTC
Last enriched: 08/24/2026, 15:04:56 UTC
Last updated: 08/24/2026, 16:41:27 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.