CVE-2024-54756 is a remote code execution vulnerability in GZDoom Team's GZDoom v4.13.1. The vulnerability exists in the ZScript function, which improperly handles ZScript source files embedded in PK3 archives. An attacker can craft a malicious PK3 file containing a specially crafted ZScript source file that, when loaded by GZDoom, results in arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept exploit for an arbitrary code execution vulnerability in GZDoom versions 4.13.0 and 4.13.1, specifically targeting the ZScript scripting engine. The exploit consists of two main files: 'zscript.zs' (the malicious ZScript code) and 'MAPINFO' (which registers the event handler). The README.md provides detailed background, usage instructions, and technical explanation of the vulnerabilities exploited. The exploit leverages two vulnerabilities: (1) improper handling of huge arrays in ZScript, allowing out-of-bounds read/write and memory overlap, and (2) the presence of memory regions with both write and execute permissions (RWX), enabling the attacker to inject and execute shellcode. The ZScript code allocates a massive array to scan memory, locates an RWX region, writes shellcode, and then triggers its execution. The default payload is a bash reverse shell connecting to localhost:1337, but this can be changed by modifying the shell command in the script. The exploit is operational as a proof-of-concept and is intended for Linux systems. It requires the victim to load a malicious PK3 file in GZDoom. The exploit demonstrates full code execution capabilities and provides a reverse shell to the attacker. No external network endpoints are hardcoded except for the local reverse shell, but the payload can be modified for remote access. The repository is well-documented and provides a clear demonstration of the vulnerability and exploitation process.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.