# Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files

> Synacktiv researcher Thomas Dubier disclosed multiple heap overflow vulnerabilities in Titan Quest: Anniversary Edition v2.10.21415 (Engine.dll), reachable via malicious .lvl level-descriptor files and .pfx particle-effect files distributed as community custom maps. A working exploit chain achieves remote code execution on Windows 11 by combining an integer-overflow-driven heap overflow, 32-bit address-space exhaustion to defeat ASLR, Segment Heap feng shui, and a vtable-hijack/ROP pivot into attacker-supplied shellcode. No CVE has been assigned and the vendor (THQ Nordic) has not confirmed a patch.

- **Published:** 2026-08-02T00:00:00Z
- **Last reviewed:** 2026-08-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1817
- **ID:** TL-2026-1817
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Synacktiv's 29 July 2026 publication "Exploiting Titan Quest" documents a full exploit chain against the game engine (Engine.dll, a 32-bit module) shipped with Titan Quest: Anniversary Edition v2.10.21415, tested against a Windows 11 Professional VM (build 10.0.26200).

The research began with an attack-surface enumeration: the researcher identified 49 distinct methods in Engine.dll that accept a BinaryReader structure as input, i.e. the full set of file-parsing entry points reachable from untrusted .map/.lvl/.wrl/.pfx content, then reverse-engineered these formats' deserialization routines to find exploitable bugs among them.

Two distinct memory-safety bugs were identified. First, GAME::ImpassableData::Load, invoked when parsing a .lvl level-descriptor file's CHUNK_TYPE_IMPASSABLE_DATA (0x03) block, allocates a byte buffer sized by multiplying attacker-controlled width and height fields; this multiplication can integer-overflow past 32 bits, producing an undersized allocation, after which an unvalidated count-sized memcpy (memcpy(buffer, binaryRead->currentPtr, count)) overflows the heap buffer. Second, GAME::EmitterData::InternalBinaryRead, invoked when parsing a .pfx particle-effect file, copies six variable-length arrays (strings, boolean arrays, DWORD arrays, curve data) read directly from the file into a fixed-size GAME::EmitterData structure with no bounds checks, producing further heap overflows; the researcher assessed these as less exploitable because the allocation size itself is uncontrolled.

The demonstrated exploit chain weaponizes the ImpassableData bug. First, GAME::Water::Load is abused for heap feng shui: many WaterType objects (up to 128 layers, texture-name strings up to 1MB each) are allocated to fill the heap, chunks sized like a Level object (~0x4000+ bytes, forcing Windows 11's Segment Heap) are allocated, and reference-counted object lifetimes are manipulated so that freeing chunk 2 then chunk 4 in a FIFO pattern creates predictable "holes" that the next same-sized allocations land into — first the Level object, then the Impassable Buffer — in adjacent, deterministic positions. Second, ASLR is defeated by address-space exhaustion: roughly 128MB of WaterType allocations (128 layers x up to 1MB texture-name strings) are sprayed so allocation addresses become predictable in their lower 12 bits (landing on XXXXX000-aligned pages), and a repeated payload structure is embedded inside each WaterType's noiseTextureName field for later use. Third, a crafted .lvl file with an oversized CHUNK_TYPE_IMPASSABLE_DATA block triggers the heap overflow to corrupt the adjacent Level object's _water pointer, redirecting it into the fabricated Water object planted via the noiseTextureName spray. Fourth, a CHUNK_TYPE_WATER (0x09) block causes GAME::Level::NewWater to run against the corrupted pointer; its destructor invokes an indirect vtable call — (*layer)->vtable->release(*layer, 1) — on the corrupted WaterLayer object, redirecting control flow to a ROP gadget at 0x10021b91 (xchg esp, eax; pop edi; pop esi; pop ebp; pop ebx; ret) that pivots the stack into heap-resident attacker data. From there a ROP-driven call into a native memory-protection API performs the standard heap-executable transformation, and shellcode execution on the corrupted heap completes the chain.

The distribution/attack vector is entirely file-based and social: Titan Quest supports community-authored custom maps that players manually copy into %USERPROFILE%\Documents\My Games\Titan Quest - Immortal Throne\custommaps. A malicious .map (which bundles .lvl/.tga content), .lvl, or .pfx file shared through the game's active modding community is sufficient to reach the vulnerable parsers — no network exposure or authentication bypass is required, but the victim must be persuaded to install third-party content. This mirrors a real-world precedent disclosed independently around the same period: the "Meccha Chameleon" Steam Workshop incident (reported 23 July 2026), in which a workshop custom map for a different Unreal Engine 5 title bypassed Steam Workshop review by hiding a Blueprint asset (ReceiveBeginPlay-triggered) that wrote and executed a PowerShell/batch dropper (s.bat, fetching a second-stage payload from a hardcoded C2 host at 31.57.34.228) — demonstrating the same category of "custom map as malware delivery" abuse of a game's modding pipeline that Synacktiv's Titan Quest research documents.

Synacktiv began the research 23 March 2026, contacted the vendor (THQ Nordic) 15 April 2026 and again 2 May 2026, and published the full technical writeup with a working PoC video on 29 July 2026 with no CVE assigned and no vendor-confirmed patch. The GOG release of the game additionally ships development tooling (Editor.exe for level design, MapCompiler.exe for compiling .map files, and PSEditor.exe for particle effects) that lowers the bar for crafting structurally valid malicious content, and analysis of bundled binaries (e.g., a UPX-packed DevIL.dll, unpacked via `upx -d DevIL.dll`) was required to fully reverse the file formats involved.

## MITRE ATT&CK

- T1592.002 Software
- T1592.004 Client Configurations
- T1595.002 Vulnerability Scanning
- T1588.006 Vulnerabilities
- T1588.002 Tool
- T1587.004 Exploits
- T1587.001 Malware
- T1608.001 Upload Malware
- T1195.002 Compromise Software Supply Chain
- T1204.002 Malicious File
- T1203 Exploitation for Client Execution
- T1106 Native API
- T1211 Exploitation for Stealth
- T1027.009 Embedded Payloads
- T1027.002 Software Packing
- T1140 Deobfuscate/Decode Files or Information

## Sources

- [Exploiting Titan Quest](https://www.synacktiv.com/en/publications/exploiting-titan-quest.html)
- [Downloaded a custom map for Meccha Chameleon recently? A researcher says it may have installed malware on your PC](https://www.windowscentral.com/gaming/pc-gaming/meccha-chameleon-steam-workshop-malware)
- [Workshop map for MECCHA CHAMELEON is a malware dropper (full breakdown)](https://medium.com/@FeintBE/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown-d1ac29565265)
- [These Popular Steam Workshop Custom Maps Secretly Install PC Malware](https://hothardware.com/news/these-popular-steam-workshop-custom-maps-secretly-install-pc-malware)
- [Titan Quest Anniversary Edition on Steam](https://store.steampowered.com/app/475150/Titan_Quest_Anniversary_Edition/)
- [THQ Nordic - Official Site](https://thqnordic.com/)
- [Titan Quest (Wikipedia)](https://en.wikipedia.org/wiki/Titan_Quest)
- [Heap feng shui (Wikipedia)](https://en.wikipedia.org/wiki/Heap_feng_shui)
- [corelan-heap advanced Windows heap exploitation training](https://www.corelan-training.com/index.php/heap/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1817
