Threat reportVulnerabilityTL-2026-1817

Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files

highACTIVE

Heap Overflow Chain in Titan Quest (TL-2026-1817) is a high-severity software vulnerability, first published 2026-08-02. It has no confirmed attribution, affects THQ Nordic Titan Quest: Anniversary Edition, maps to 16 MITRE ATT&CK techniques (T1027.002, T1027.009, T1106), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1817

Threat ID
TL-2026-1817
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
gaming, entertainment, consumersoftware
Target regions
Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in Heap Overflow Chain in Titan Quest

Malware and tooling: ARCExplorer, MapCompiler.exe, PSEditor.exe, SystemInformer, UPX

How Heap Overflow Chain in Titan Quest works

Synacktiv researcher Thomas Dubier disclosed multiple heap overflow vulnerabilities in Titan Quest: Anniversary Edition v2.10.21415 (Engine.dll), reachable via malicious .lvl level-descriptor files and .pfx particle-effect files distributed as community custom maps. A working exploit chain achieves remote code execution on Windows 11 by combining an integer-overflow-driven heap overflow, 32-bit address-space exhaustion to defeat ASLR, Segment Heap feng shui, and a vtable-hijack/ROP pivot into attacker-supplied shellcode. No CVE has been assigned and the vendor (THQ Nordic) has not confirmed a patch.

Synacktiv's 29 July 2026 publication "Exploiting Titan Quest" documents a full exploit chain against the game engine (Engine.dll, a 32-bit module) shipped with Titan Quest: Anniversary Edition v2.10.21415, tested against a Windows 11 Professional VM (build 10.0.26200).

The research began with an attack-surface enumeration: the researcher identified 49 distinct methods in Engine.dll that accept a BinaryReader structure as input, i.e. the full set of file-parsing entry points reachable from untrusted .map/.lvl/.wrl/.pfx content, then reverse-engineered these formats' deserialization routines to find exploitable bugs among them.

Two distinct memory-safety bugs were identified. First, GAME::ImpassableData::Load, invoked when parsing a .lvl level-descriptor file's CHUNK_TYPE_IMPASSABLE_DATA (0x03) block, allocates a byte buffer sized by multiplying attacker-controlled width and height fields; this multiplication can integer-overflow past 32 bits, producing an undersized allocation, after which an unvalidated count-sized memcpy (memcpy(buffer, binaryRead->currentPtr, count)) overflows the heap buffer. Second, GAME::EmitterData::InternalBinaryRead, invoked when parsing a .pfx particle-effect file, copies six variable-length arrays (strings, boolean arrays, DWORD arrays, curve data) read directly from the file into a fixed-size GAME::EmitterData structure with no bounds checks, producing further heap overflows; the researcher assessed these as less exploitable because the allocation size itself is uncontrolled.

The demonstrated exploit chain weaponizes the ImpassableData bug. First, GAME::Water::Load is abused for heap feng shui: many WaterType objects (up to 128 layers, texture-name strings up to 1MB each) are allocated to fill the heap, chunks sized like a Level object (~0x4000+ bytes, forcing Windows 11's Segment Heap) are allocated, and reference-counted object lifetimes are manipulated so that freeing chunk 2 then chunk 4 in a FIFO pattern creates predictable "holes" that the next same-sized allocations land into — first the Level object, then the Impassable Buffer — in adjacent, deterministic positions. Second, ASLR is defeated by address-space exhaustion: roughly 128MB of WaterType allocations (128 layers x up to 1MB texture-name strings) are sprayed so allocation addresses become predictable in their lower 12 bits (landing on XXXXX000-aligned pages), and a repeated payload structure is embedded inside each WaterType's noiseTextureName field for later use. Third, a crafted .lvl file with an oversized CHUNK_TYPE_IMPASSABLE_DATA block triggers the heap overflow to corrupt the adjacent Level object's _water pointer, redirecting it into the fabricated Water object planted via the noiseTextureName spray. Fourth, a CHUNK_TYPE_WATER (0x09) block causes GAME::Level::NewWater to run against the corrupted pointer; its destructor invokes an indirect vtable call — (*layer)->vtable->release(*layer, 1) — on the corrupted WaterLayer object, redirecting control flow to a ROP gadget at 0x10021b91 (xchg esp, eax; pop edi; pop esi; pop ebp; pop ebx; ret) that pivots the stack into heap-resident attacker data. From there a ROP-driven call into a native memory-protection API performs the standard heap-executable transformation, and shellcode execution on the corrupted heap completes the chain.

The distribution/attack vector is entirely file-based and social: Titan Quest supports community-authored custom maps that players manually copy into %USERPROFILE%\Documents\My Games\Titan Quest - Immortal Throne\custommaps. A malicious .map (which bundles .lvl/.tga content), .lvl, or .pfx file shared through the game's active modding community is sufficient to reach the vulnerable parsers — no network exposure or authentication bypass is required, but the victim must be persuaded to install third-party content. This mirrors a real-world precedent disclosed independently around the same period: the "Meccha Chameleon" Steam Workshop incident (reported 23 July 2026), in which a workshop custom map for a different Unreal Engine 5 title bypassed Steam Workshop review by hiding a Blueprint asset (ReceiveBeginPlay-triggered) that wrote and executed a PowerShell/batch dropper (s.bat, fetching a second-stage payload from a hardcoded C2 host at 31.57.34.228) — demonstrating the same category of "custom map as malware delivery" abuse of a game's modding pipeline that Synacktiv's Titan Quest research documents.

Synacktiv began the research 23 March 2026, contacted the vendor (THQ Nordic) 15 April 2026 and again 2 May 2026, and published the full technical writeup with a working PoC video on 29 July 2026 with no CVE assigned and no vendor-confirmed patch. The GOG release of the game additionally ships development tooling (Editor.exe for level design, MapCompiler.exe for compiling .map files, and PSEditor.exe for particle effects) that lowers the bar for crafting structurally valid malicious content, and analysis of bundled binaries (e.g., a UPX-packed DevIL.dll, unpacked via `upx -d DevIL.dll`) was required to fully reverse the file formats involved.

MITRE ATT&CK techniques used in TL-2026-1817

Defense Evasion

T1027.002 Software Packing; T1027.009 Embedded Payloads; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth

Execution

T1106 Native API; T1203 Exploitation for Client Execution; T1204.002 Malicious File

Initial Access

T1195.002 Compromise Software Supply Chain

Resource Development

T1587.001 Malware; T1587.004 Exploits; T1588.002 Tool; T1588.006 Vulnerabilities; T1608.001 Upload Malware

Reconnaissance

T1592.002 Software; T1592.004 Client Configurations; T1595.002 Vulnerability Scanning

Affected products and versions in Heap Overflow Chain in Titan Quest

  • THQ Nordic — Titan Quest: Anniversary Edition
    Vulnerable versions: v2.10.21415

Remediation for Heap Overflow Chain in Titan Quest

Patches

  • No vendor patch confirmed as of the 29 July 2026 disclosure; THQ Nordic was contacted 15 April 2026 and 2 May 2026 with no confirmed remediation

Immediate actions

  • Do not install third-party or community custom maps (.map/.lvl/.pfx) from untrusted sources into the Titan Quest: Anniversary Edition custommaps folder
  • Restrict or monitor write access to %USERPROFILE%\Documents\My Games\Titan Quest - Immortal Throne\custommaps
  • Avoid running Titan Quest: Anniversary Edition with elevated privileges or on systems used for sensitive work while unpatched

Workarounds

  • Disable or remove the custommaps directory/feature if not actively used
  • Only install custom maps from verified, trusted community sources
  • Apply file-integrity monitoring to the custommaps directory to detect newly dropped .map/.lvl/.pfx files

Longer-term hardening

  • Vendor should validate width, height, and count fields against actual buffer bounds in GAME::ImpassableData::Load before allocation and copy
  • Vendor should bounds-check all variable-length array reads in GAME::EmitterData::InternalBinaryRead against the fixed GAME::EmitterData structure size
  • Migrate Engine.dll to a 64-bit build to gain full ASLR entropy and materially raise the cost of address-space-exhaustion attacks
  • Enable Control Flow Guard (CFG) and additional exploit mitigations on Engine.dll and its dependent modules
  • Audit all 49 BinaryReader-consuming deserialization entry points in Engine.dll, not just the two documented here, for the same class of unvalidated-size/unbounded-copy defects

Weaknesses (CWE) in Heap Overflow Chain in Titan Quest

CWE-190, CWE-122, CWE-787, CWE-131

Timeline of Heap Overflow Chain in Titan Quest

  • Titan Quest: Anniversary Edition originally released on Steam, establishing the codebase, Engine.dll, and community custom-map/modding ecosystem later found vulnerable.
  • Synacktiv begins vulnerability research into Titan Quest: Anniversary Edition's custom map/particle file parsing in Engine.dll.
  • Synacktiv makes initial contact with THQ Nordic to disclose the discovered heap overflow vulnerabilities.
  • Synacktiv sends a follow-up disclosure contact to THQ Nordic; no confirmed vendor response is recorded.
  • The "Meccha Chameleon" Steam Workshop custom-map malware-dropper incident is publicly reported (a different Unreal Engine 5 title), later cited as real-world validation of the game-modding distribution vector abused in the Titan Quest exploit chain.
  • As of publication, THQ Nordic has not confirmed a patch or fix timeline despite two prior disclosure contacts.
  • As of publication, no CVE identifier has been requested or assigned for either the GAME::ImpassableData::Load or GAME::EmitterData::InternalBinaryRead vulnerabilities.
  • Synacktiv publishes "Exploiting Titan Quest," the full technical writeup of the heap overflow chain, distribution vector, and exploit primitives, with no CVE assigned.
  • Synacktiv successfully demonstrates the full exploit chain achieving remote code execution in a Windows 11 (build 10.0.26200) virtual machine, recorded on video.

Sources cited for Heap Overflow Chain in Titan Quest

Detection coverage for TL-2026-1817

As of 2026-08-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1817 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats