CVE-2004-1958

Unreal Engine - Directory Traversal and Arbitrary File Write via UMOD File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1958. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit demonstrates a local file overwrite vulnerability in the Unreal Tournament Engine by manipulating the UMOD manifest.ini file. It allows arbitrary file writing, potentially leading to a denial of service condition.

Description

Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · cremotemultiple
https://www.exploit-db.com/exploits/24041

This exploit demonstrates a local file overwrite vulnerability in the Unreal Tournament Engine by manipulating the UMOD manifest.ini file. It allows arbitrary file writing, potentially leading to a denial of service condition.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Unreal Tournament <= 451b, Unreal Tournament 2003 <= 2225
No auth needed
Prerequisites: Access to the system where the vulnerable game is installed · Ability to create or modify UMOD files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15942
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108267310519459&w=2
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10196

Scores

EPSS 0.0244
EPSS Percentile 82.2%

Details

Status published
Products (7)
epic_games/unreal_engine 433
epic_games/unreal_engine 436
epic_games/unreal_tournament 451b
epic_games/unreal_tournament_2003 2199_macos
epic_games/unreal_tournament_2003 2199_win32
epic_games/unreal_tournament_2003 2225_macos
epic_games/unreal_tournament_2003 2225_win32
Published Dec 31, 2004
Tracked Since Feb 18, 2026