CVE-2025-34124 - CVE House
Back to Database
Status published High CVE-2025-34124

Heroes of Might and Magic III .h3m Map File Buffer Overflow

Vulnerability Description

A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34124

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Pierre Lindblad
  • John AAkerblo

Affected Vendor

The 3DO Company

View all reports →

Affected Software

Heroes of Might and Magic III
Vulnerable Versions:
Complete 4.0.0.0, HD Mod 3.808 build 9, Demo 1.0.0.0

Timeline

Official Publish: July 16th, 2025
Last Modified: April 7th, 2026
Added to House: July 22nd, 2026

CVSS Vectors