GameMaker IDE Integer Overflow Vulnerability Leading to Denial-of-Service
Vulnerability
An integer overflow vulnerability has been identified in GameMaker IDE versions prior to 2024.14.0. This vulnerability can be exploited to cause application crashes, leading to denial-of-service (DoS) conditions. The issue arises in projects that use the network_create_server() function, where malformed or oversized packets can be processed, causing the application to terminate unexpectedly.
Impact
Exploitation of this vulnerability causes application crashes, creating denial-of-service conditions where users are unable to access or use the game or application.
Remediation
Users are advised to update their GameMaker IDE to version 2024.14.0 or higher. After updating, it is crucial to recompile and export all affected projects using the 2024.14 runtime. Distribute these updated versions to users.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
