peter bassill · operator
$ cve CVE-2022-47949 JSON

CVE-2022-47949

9.8
CRITICAL · CVSS 3.1 · EPSS 23.1% (pctl 98)

Patch early

EPSS 23.1% — above the 10% action threshold.

Description

The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS23.15% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2022-12-24
Last modified2026-06-17

Affected (9)

VendorProduct
nintendoanimal crossing\
nintendoarms
nintendomario kart 7
nintendomario kart 8
nintendosplatoon
nintendosplatoon 2
nintendosplatoon 3
nintendosuper mario maker 2
nintendoswitch sports

References

→ the Explorer  ·  watch your stack  ·  NVD