VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-1522

CVE-2004-1522

Description

Army Men RTS 1.0 contains a format string vulnerability in the player nickname field, allowing remote attackers to crash the server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Army Men RTS 1.0 contains a format string vulnerability in the player nickname field, allowing remote attackers to crash the server.

Vulnerability

Army Men RTS version 1.0 is affected by a format string vulnerability in the game server. The server processes the player's nickname using a format string function without proper sanitization. When a player joins a server with a nickname containing format string specifiers (e.g., %n%n%n), the server crashes. The bug is present in the server component and requires no special configuration beyond the default game setup [1].

Exploitation

An attacker can exploit this vulnerability by connecting to a game server and setting a nickname that includes format string specifiers such as %n%n%n. No authentication or prior access is needed; the attacker simply joins the server with the malicious nickname. The server immediately crashes upon processing the nickname, causing a denial of service [1].

Impact

Successful exploitation results in a denial of service (application crash) of the game server. The reference does not indicate any possibility of code execution or data compromise; the impact is limited to server unavailability [1].

Mitigation

No fix has been released for this vulnerability. The game is no longer supported by the vendor, and no workarounds are provided. Users are advised to avoid playing on untrusted servers or to discontinue use of the software. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.