CVE-2022-47949

CRITICALCVSS 9.8/10EPSS 16.89%

Last modified

CVE-2022-47949 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. EPSS estimates a 16.89% chance of exploitation in the next 30 days.

Description

The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
16.89%

96.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NintendoAnimal Crossing\< 2.0.6
NintendoArms< 5.4.1
NintendoMario Kart 7< 1.2
NintendoMario Kart 8< 2.1.0
NintendoMario Kart 8All versions
NintendoSplatoonAll versions
NintendoSplatoon 2< 5.5.1
NintendoSplatoon 3All versions
NintendoSuper Mario Maker 2< 3.0.2
NintendoSwitch SportsAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-47949?
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.
How severe is CVE-2022-47949?
CVE-2022-47949 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 16.89% probability of exploitation in the next 30 days.
How do I fix CVE-2022-47949?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-47949?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST