CVE-2022-47949
9.8
CRITICAL · CVSS 3.1 · EPSS 23.1% (pctl 98)
Patch early
EPSS 23.1% — above the 10% action threshold.
Description
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 23.15% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-12-24 |
| Last modified | 2026-06-17 |
Affected (9)
| Vendor | Product |
|---|---|
| nintendo | animal crossing\ |
| nintendo | arms |
| nintendo | mario kart 7 |
| nintendo | mario kart 8 |
| nintendo | splatoon |
| nintendo | splatoon 2 |
| nintendo | splatoon 3 |
| nintendo | super mario maker 2 |
| nintendo | switch sports |
→ the Explorer · watch your stack · NVD