Project64 Buffer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in Project64 version 2.3.2, specifically within the Plugin Directory settings field. This vulnerability allows local attackers to crash the application by entering an excessively long string. By inputting a 6000-byte payload into the Plugin Directory field through the Options > Settings > Directories interface, attackers can trigger an application crash when the settings are reopened.

Impact

Exploitation of this vulnerability causes the application to crash, leading to a denial-of-service condition.

Reproduction

To reproduce this vulnerability, open Project64 version 2.3.2 on a Windows 7 32-bit system. Navigate to 'Options' > 'Settings' > 'Directories'. Paste a 6000-byte payload into the 'Plugin Directory' field and ensure it is selected. Click 'Apply' and then 'OK'. Reopen the 'Options' > 'Settings' menu to observe the application crash.

Added: Apr 26, 2026, 10:32 PM
Updated: Apr 26, 2026, 10:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
0.0
relevance
6.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.