CVE-2004-1500

Freeform Interactive Purge Jihad - Denial of Service

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1500. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit demonstrates a format string vulnerability in the Lithtech game engine (F.E.A.R. <= 1.08) via malformed UDP packets sent to port 27888. It leverages incorrect usage of printf-type functions to trigger a denial-of-service or potential remote code execution.

Description

Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · cremotemultiple
https://www.exploit-db.com/exploits/24724

This exploit demonstrates a format string vulnerability in the Lithtech game engine (F.E.A.R. <= 1.08) via malformed UDP packets sent to port 27888. It leverages incorrect usage of printf-type functions to trigger a denial-of-service or potential remote code execution.

Classification
Working Poc 95%
Attack Type
Rce | Dos
Complexity
Moderate
Reliability
Reliable
Target: F.E.A.R. <= 1.08 (Lithtech game engine)
No auth needed
Prerequisites: Network access to the target server · UDP port 27888 open
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11610
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17972
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17317
Third Party Advisory x_refsource_misc
http://aluigi.altervista.org/adv/lithfs-adv.txt
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13116/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109969394601331&w=2

Scores

EPSS 0.0188
EPSS Percentile 76.8%

Details

Status published
Products (13)
freeform_interactive/purge_jihad 2.2.1
monolith_productions/alien_versus_predator 2.1.0.9.6
monolith_productions/blood 2.2.1
monolith_productions/contract_jack 1.1
monolith_productions/global_operations 2.0
monolith_productions/global_operations 2.1
monolith_productions/kiss_psycho_circus 1.13
monolith_productions/legends_of_might_and_magic 1.1
monolith_productions/no_one_lives_forever 1.0.004
monolith_productions/no_one_lives_forever 2.1.3
... and 3 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026