CVE-2022-47949: Nintendo Animal Crossing: New Horizons
Critical severity, CVSS 9.8. EPSS: 23.1% chance of exploitation in the next 30 days.
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.
Affected products
- Nintendo Animal Crossing: New Horizons: before 2.0.6 (fixed in 2.0.6)
- Nintendo Arms: before 5.4.1 (fixed in 5.4.1)
- Nintendo Mario Kart 7: before 1.2 (fixed in 1.2)
- Nintendo Mario Kart 8: before 2.1.0 (fixed in 2.1.0); affected versions not specified
- Nintendo Splatoon: any version
- Nintendo Splatoon 2: before 5.5.1 (fixed in 5.5.1)
- Nintendo Splatoon 3: any version
- Nintendo Super Mario Maker 2: before 3.0.2 (fixed in 3.0.2)
- Nintendo Switch Sports: any version
Published 2022-12-24. Last modified 2026-06-17.