GameMaker IDE Integer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

An integer overflow vulnerability has been identified in GameMaker IDE versions prior to 2024.14.0. This vulnerability can be exploited to cause application crashes, leading to denial-of-service (DoS) conditions. The issue arises in projects that use the network_create_server() function, where malformed or oversized packets can be processed, causing the application to terminate unexpectedly.

Impact

Exploitation of this vulnerability causes application crashes, creating denial-of-service conditions where users are unable to access or use the game or application.

Remediation

Users are advised to update their GameMaker IDE to version 2024.14.0 or higher. After updating, it is crucial to recompile and export all affected projects using the 2024.14 runtime. Distribute these updated versions to users.

Added: Oct 31, 2025, 3:26 PM
Updated: Oct 31, 2025, 3:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.