CS:GO: From Zero to 0-day — Neodyme
We identified three independent remote code execution (RCE) vulnerabilities in the popular Counter-Strike: Global Offensive game. Each vulnerability can be triggered when the game client connects to our malicious python CS:GO server. This post details our journey through the CS:GO binary and conducts a technical deep dive into various identified bugs. We conclude by presenting a proof of concept (POC) exploit that leverages four different logic bugs into remote code execution in the game's client, triggered when a client connects to the server.
Authored by: Felipe Alain TL;DR ¶ We identified three independent remote code execution (RCE) vulnerabilities in the popular Counter-Strike: Global Offensive game. Each vulnerability can be triggered when the game client connects to our malicious python CS:GO server. This post details our journey through the CS:GO binary and conducts a technical deep dive into various identified bugs. We conclude by presenting a proof of concept (POC) exploit that leverages four different logic bugs into remote code execution in the game’s client, triggered when a client connects to the server. Introduction ¶
Explore this link on the map →related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- Reverse engineering Claude's CVE-2026-2796 exploit \ Anthropicred.anthropic.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Security incident disclosure — July 2026huggingface.co
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- Multiple Vulnerabilities in Rocket Software UniData's UniRPC server (Fixed) | Rapid7 Blograpid7.com
- From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code - Project Zerogoogleprojectzero.blogspot.com
- Four Days of Go – Evan Millerevanmiller.org
- All learning materials - detailed | Web Security Academyportswigger.net
- Zenbleedlock.cmpxchg8b.com
- Memory Safety Vulnerabilities | Computer Securitytextbook.cs161.org