CVE-2024-39840

HIGH

Factorio <1.1.101 - RCE

Title source: llm

Description

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.

Exploits (1)

nomisec WORKING POC
by writegsqword · poc
https://github.com/writegsqword/CVE-2024-39840-POC

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Published Jun 29, 2024
Tracked Since Feb 18, 2026