Buffer Overflow Vulnerability in UFO: Alien Invasion by VLC
CVE-2009-10006
Key Information:
- Vendor
Ufo: Alien Invasion Project
- Status
- Vendor
- CVE Published:
- 22 August 2025
Badges
What is CVE-2009-10006?
UFO: Alien Invasion versions up to and including 2.2.1 are vulnerable to a buffer overflow exploit in the integrated IRC client. This vulnerability allows attackers to craft a specific numeric reply (specifically a 001 message) that the application fails to properly validate, leading to a stack-based buffer overflow. This flaw can potentially corrupt control flow structures, resulting in arbitrary code execution without requiring user interaction beyond starting the game. The automatic handling of IRC connections poses a significant risk, necessitating immediate attention to mitigate exploitation.
Affected Version(s)
UFO: Alien Invasion Windows * <= 2.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved