On days during
WTF fuzzer testing, I discovered a stack-based 4 byte buffer overflow in Counter-Strike 1.6.
The vulnerability resides in CL_ParseServerMessage, within one of the client-side message parsing functions.
This results in Server -> Client RCE.
All versions are affected, including pirated ones.
Other games on the same engine are likely vulnerable as well.
The GoldSrc engine makes it an attractive target. It ships without ASLR, CFG and other mitigations, which makes exploitation relatively easy.
Attached is a short PoC video, DEP is disabled on the victim system because I'm lazy ass to build a ROP chain.
I decided to not report it to the Valve, so expect writeup soon.