Announcement

Collapse
No announcement yet.

Ubisoft rush to fix security hole exposed

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Ubisoft rush to fix security hole exposed

    Ubisoft rush to fix security hole exposed by plug-in
    Games affected include the massively popular Assassin's Creed series Mobile games pay off for Ubisoft
    Games maker Ubisoft has been forced to release an emergency patch to fix a security hole discovered in its Uplay application.

    A web browser add-on reportedly left users open to outside attackers gaining control of their computer.

    The Uplay software is bundled with major titles like Assassin's Creed.

    "We recommend that all Uplay users update their Uplay PC application without a Web browser open," Ubisoft said.

    "This will allow the plug-in to update correctly.

    "An updated version of the Uplay PC installer with the patch also is available from Uplay.com."

    Uplay is a system that allows gamers to earn points and rewards for performance which are logged online.

    As well as the multi-million-selling Assassin's Creed series, Uplay is also used with games such as Call of Juarez: San Francisco, Just Dance 3 and several titles in the Tom Clancy series.

    Vacation discovery

    The spokesman added: "Ubisoft takes security issues very seriously, and we will continue to monitor all reports of vulnerabilities within our software and take swift action to resolve such issues."

    The flaw was discovered by Tavis Ormandy, a Google employee.

    On a mailing list for information security experts and hobbyists, he wrote: "While on vacation recently I bought a video game called Assassin's Creed Revelations. I didn't have much of a chance to play it, but it seems fun so far.

    "However, I noticed the installation procedure creates a browser plug-in for it's accompanying Uplay launcher, which grants unexpectedly (at least to me) wide access to websites."

    It was discovered that any website could force users with the plug-in to open any program on their PC.

    To demonstrate this, one security researcher created a website proving the exploits' existence. When a person visited the website, the calculator program would launch.

    While the calculator is harmless, experts warned that the technique could be used to launch a potentially malicious program.

    #2
    Good to know.
    [img]https://farm5.staticflickr.com/4373/35734799443_53cb20ef13_z.jpg[/img]


    Killed by CLRs since 2004. WOOT!
    Support Cainslair. Donate here! [url]http://www.cainslair.org/billspaypal.php?[/url]

    Comment

    Cain's Lair Forums Statistics

    Collapse

    Topics: 26,188   Posts: 269,861   Members: 6,183   Active Members: 4
    Welcome to our newest member, Fermin13Q.

    Today's Birthdays

    Collapse

    There are no members with birthdays today.

    Top Active Users

    Collapse

    There are no top active users.

    More Posts

    Collapse

    • Reply to hey yall!
      by Sirex
      All sorted now, even updated the email on the account.

      Been quite a few of us catching up in the discord the last few days ...
      7 Mar 2025, 10:03 AM
    • Reply to hey yall!
      by Pidgeot_Girl
      Glad to hear you're doing well Apache and congratulations on the business!! Only thing I'm playing is BO6 these days on the weekends!
      2 Mar 2025, 01:55 PM
    • Reply to hey yall!
      by Apache Warrior
      Sirex should be able to recover his log in and change the password. He would then login and change the password.
      I am not playing anything right...
      2 Mar 2025, 09:04 AM
    • Reply to Hi guys!
      by Pidgeot_Girl
      Mostly playing good ol CoD BO6 on the PS5 (old habits die hard), I'll dabble into a little bit of Fallout 4. But I'm pretty much a weekend warrior, my...
      1 Mar 2025, 07:24 PM
    • Reply to hey yall!
      by Pidgeot_Girl
      Sirex!!! I will let him know! He cant remember his log in anymore but he wonders how everyone in the lair is doing, and hope everyone is doing well. Also...
      1 Mar 2025, 05:19 PM
    • Reply to hey yall!
      by Sirex
      :O hey Pidgeot!

      Long time no see and congrats on EVERYTHING!
      Good to hear all that wonderful news and I know what its like having...
      23 Feb 2025, 06:31 PM
    Working...
    X