Format string vulnerability in the Epic Games Unreal engine client, as used in multiple games, allows remote servers to execute arbitrary code via (1) the CLASS parameter in a DLMGR command, (2) a malformed package (PKG), and possibly (3) the LEVEL parameter in a WELCOME command.
| Software | From | Fixed in |
|---|---|---|
| epicgames / unreal_engine | 2 | 2.x |
| epicgames / unreal_engine | 3 | 3.x |
| epicgames / unreal_engine | 2.5 | 2.5.x |