Record summary

CVE-2025-34124 has a selected CVSS score of 8.4 (high); EIP currently links 2 catalogued exploits.

Description

A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListComplete 4.0.0.0affected
HD Mod 3.808 build 9affected
Demo 1.0.0.0affected

Proofs of concept

2

Catalogued exploits

ExploitDBHeroes of Might and Magic III - Map Parsing Arbitrary Code ExecutionExploitDB exploitby John AAkerblomNot analyzed1 file
ExploitDB

PoC details
MetasploitHeroes of Might and Magic III .h3m Map file Buffer OverflowMetasploit exploitby John AAkerblom +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

4