Vulnerability record · CVE-2004-0735 · published 27 July 2004
CVE-2004-0735: Medal of Honor LAN buffer overflow allows remote code execution
Electronic Arts · Medal Of Honor Allied Assault
Multiple Medal of Honor titles (Allied Assault, Breakthrough, Spearhead) contain a buffer overflow that is triggered while playing on a LAN. Crafted getinfo queries, connect packets, and other unspecified vectors let a remote attacker overwrite memory and run arbitrary code. The flaw matters because it is network-reachable with no authentication and affects widely played multiplayer game clients.
Description
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo query, (2) the connect packet, and other unknown vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated remote code execution with public exploit references and very high EPSS, though limited to LAN play and legacy software.
What it is
Multiple Medal of Honor titles (Allied Assault, Breakthrough, Spearhead) contain a buffer overflow that is triggered while playing on a LAN. Crafted getinfo queries, connect packets, and other unspecified vectors let a remote attacker overwrite memory and run arbitrary code. The flaw matters because it is network-reachable with no authentication and affects widely played multiplayer game clients.
Impact
A remote attacker on the same LAN can execute arbitrary code in the context of the game process, potentially taking full control of the player's machine.
Attack surface
Reachable over the network via the game's LAN multiplayer protocol, specifically getinfo queries and connect packets. No authentication or user interaction beyond joining a LAN game is required, per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV, but EPSS is 0.62108 (99.14th percentile) and SecurityFocus references are tagged Exploit and Patch, indicating public exploit code exists.
What to do
- Apply the vendor patch referenced in the SecurityFocus advisory (BID 10743) to Allied Assault, Breakthrough, and Spearhead.
- Upgrade to versions later than Allied Assault 1.11v9, Breakthrough 2.40b, and Spearhead 2.15.
- Restrict LAN play to trusted networks and segment game traffic from sensitive systems.
- Block or filter the game's LAN discovery and connect ports at network boundaries where feasible.
Detection
- Monitor for crashes or abnormal process termination in Medal of Honor game executables during LAN sessions.
- Inspect LAN traffic for malformed or oversized getinfo query and connect packets.
- Watch for unexpected child processes or outbound connections spawned by the game process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0735 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2004-0735), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.