CVE-2018-20817General(activision / call_of_duty\)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch activision call_of_duty\ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • call_of_duty\

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-23); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
call_of_duty\

6 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-23: 2Mentions · 2026-07-26: 1Mentions · 2026-08-09: 1Mentions · 2026-08-18: 1Mentions · 2026-09-05: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 1Technical Details · 2026-08-09: 1Technical Details · 2026-09-05: 103-2307-2608-0908-1809-05
Signal classification2 categories
General
583.3%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-232
General1Patch1
2026-07-261
General1
2026-08-091
General1
2026-08-181
General1
2026-09-051
General1
Full discourse6 posts
  • Kenshin9977@Kenshin9977
    General

    @shadowfr94 C'est pas du GSC ou du lua un anticheat. Tiens déjà les failles qui touchent BO2 sont liées à des buffer overflow, du C++ dans le netcode et ça se touche pas avec un mod https://nvd.nist.gov/vuln/detail/CVE-2018-20817

    Post summary

    The tweet comments that Fortnite’s (likely Battlefield 2) vulnerabilities are linked to buffer overflows in C++ netcode but provides no PoC, exploit, patch, or evidence of active exploitation.

    20000831
    25.0K followersView on X
  • tyokobo765@tyokobo567
    General

    なんかYouTubeでBO2の動画見たけどちゃんと脆弱性残ったままなんやな https://app.opencve.io/cve/CVE-2018-20817

    Post summary

    The tweet notes a YouTube video implying the vulnerability remains, but offers no additional evidence or technical details.

    00010170
    625 followersView on X
  • cherry@cherryh4ck
    General

    llevan listando cods con vulneraciones RCE desde hace casi diez años, y steam no hace NADA https://nvd.nist.gov/vuln/detail/CVE-2018-20817#match-22796487

    Post summary

    The post references CVE‑2018‑20817 as an RCE issue that has been cataloged for nearly a decade but supplies no additional details, exploits, or mitigation steps.

    0001035
    19 followersView on X
  • breakrs@breakrsx
    General

    @4Blough @broggybrogs @Pirat_Nation call of duties base server architecture is not the issue lol CVE-2018-20817 , SV_SteamAuthClient , it’s just bad bounds checks causing a buffer overflow lol

    Post summary

    The tweet highlights that CVE‑2018‑20817 is a buffer overflow caused by poor bounds checks in SV_SteamAuthClient, with no further details on PoC, exploits, or patches.

    00000142
    679 followersView on X
  • ✨ kadey 💋@kadey180_x
    General

    @jjnet123 @max_sauwce @Kivikou There was also Steam authentication RCE back in 2015 for all games including BO1: https://nvd.nist.gov/vuln/detail/CVE-2018-20817

    Post summary

    The tweet references CVE‑2018‑20817 as a 2015 Steam authentication remote code execution flaw, linking to the NVD page but providing no PoC, exploit, active usage, or patch details. It therefore represents a general mention rather than a focused claim.

    0000089
    12.6K followersView on X
  • ✨ kadey 💋@kadey180_x
    Patch

    @sadisticmfkr @jjnet123 @Kivikou All RCE fixes from 2015 are before the P2P RCE's were discovered https://nvd.nist.gov/vuln/detail/CVE-2018-20817

    Post summary

    The tweet notes that RCE fixes existed before the P2P RCEs were discovered, implying remediation was available.

    0000058
    12.6K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appactivisioncall_of_duty\_advanced_warfare--
Appactivisioncall_of_duty\_black_ops_1--
Appactivisioncall_of_duty\_blacks_ops_2--
Appactivisioncall_of_duty\_ghosts--
Appactivisioncall_of_duty\_modern_warfare_2--
Appactivisioncall_of_duty\_modern_warfare_3--

Explore more