CVE-2025-34124

A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Jul 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 22:15

Updated : 2025-07-17 21:15


NVD link : CVE-2025-34124

Mitre link : CVE-2025-34124

CVE.ORG link : CVE-2025-34124


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-121

Stack-based Buffer Overflow