CVE-2025-34124 Details
Description
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.
A stack-based buffer overflow vulnerability has been identified in Heroes of Might and Magic III Complete version 4.0.0.0, HD Mod 3.808 build 9, and the Demo version 1.0.0.0. This vulnerability arises from the object sprite name parsing logic in the game's map loading process. When a player opens a maliciously crafted .h3m map file, the exploitation of the buffer overflow could lead to arbitrary code execution. The vulnerability takes advantage of the in-game map loading mechanism, requiring the victim to manually open the compromised map file.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2025CISA-ADP
Assessed Jul 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Heroes of Might and Magic III Complete | All versions |
CPE
Remediation
| |
| Heroes of Might and Magic III HD Mod | All versions |
CPE
Remediation
| |
| Heroes of Might and Magic III Demo | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | New CVE Received | [email protected] |
Volerion