A stack-based buffer overflow exists in Nintendo Mario Kart 8 Deluxe before version 3.0.3, within the LAN/LDN local multiplayer implementation. The vulnerability is triggered during deserialization of session information from a malformed browse-reply packet. An attacker, either on the same LAN or within wireless proximity (LDN), can send a crafted packet to a victim who has only opened the 'Wireless Play' or 'LAN Play' menu, without needing the victim to join a session. The flaw is due to incorrect use of the Nintendo Pia library, leading to unsafe memory operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-45200, a stack-based buffer overflow vulnerability in Mario Kart 8 Deluxe's LAN multiplayer protocol (specifically in the handling of 'browse-reply' packets). The repository contains three files: a license, a detailed README.md explaining the vulnerability and its context, and the main exploit script 'kartlanpwn-poc.py'. The exploit works by acting as a fake room host on the local network, listening for UDP packets on port 30000 (the port used by the game's LAN discovery protocol). When a Nintendo Switch running a vulnerable version of Mario Kart 8 Deluxe enters the 'LAN Play' menu, it sends a discovery packet to which the script responds with a specially crafted 'browse-reply' packet. This packet contains an application data field that is intentionally oversized, causing a stack buffer overflow in the game's process and resulting in a crash (denial of service). The exploit demonstrates control over certain CPU registers but does not achieve reliable code execution due to platform mitigations (ASLR, NX, etc.). The PoC is written in Python and is intended for research and demonstration purposes only. It targets Nintendo Switch consoles running Mario Kart 8 Deluxe versions up to 3.0.1 (3.0.2 for China/Tencent) and requires the attacker and victim to be on the same local network. The exploit does not provide a shell or persistent access, but it does demonstrate the vulnerability's impact and could potentially be extended if additional vulnerabilities (such as an information leak) are found.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.