Security hole found and fixed in Ubisoft browser plugin

Security hole found and fixed in Ubisoft browser plugin

Game publisher Ubisoft is in trouble again, after a security hole was found that could potentially let attackers remotely execute programs on people's PCs.

Ubisoft is a company renowned among PC gamers for two major things. The first is that it produces some truly excellent games, while the second is that its PC game development is driven by a deep-seated belief that all PC gamers are pirates and need to be policed accordingly.

This has led to a history of antagonism with PC gamers, and DRM tactics that are a constant source of contention. Last decade it was one of the biggest proponents of the notorious Starforce copy protection technology, and its current system involves having a constant connection to Ubisoft’s servers in order to play games (if your connection drops the game pauses and won’t continue until it returns).

This system, which ties into Ubisoft’s Uplay network, has been plagued with issues – the most recent of which were outages that effected people who had purchased Ubisoft games during Steam’s latest sale, leaving them unable to play. But while the DRM by its very nature is highly contentious issues, the latest scandal to hit the games publisher revolves around a different aspect of the Uplay network.

It turns out that the Uplay client software stealthily installs browser plugins when you install a Ubisoft game on your PC. This plugin is designed to allow the web client to launch games directly, and is something most users have been unaware even existed.

According to a post on Seclists by Tavis Ormandy, an engineer from Google, the plugin was capable of executing any application remotely, not just Ubisoft games.  This was rapidly turned into a proof of concept test that enabled people to launch Windows Calculator with a few lines of simple code. Such a security hole is potentially massive, and could well have been engineered to run malicious applications via a seemingly innocuous web link.

It took less than half a day after the exploit was first posted for Ubisoft to deploy a patch to its Uplay software that ensured the plugin could only run Uplay titles. To get this fix Ubisoft reccomends either running Uplay without a browser open to force an update or to download and install the latest client from the Uplay website.

Oddly though, there has been no statement made on the Uplay website itself, no emails to people with Uplay accounts or any kind of general warning that there is a security hole needing to be plugged.

The fix means that the stealth browser plugin still exists; it just can’t run non-Ubisoft sanctioned applications. Given that the mere existence of the plugin has been enough to enrage some gamers, disabling it completely is probably still a good option. This can be done by going to your browser’s plugin page and disabling or removing the offending Uplay Plugin. In Firefox this is done by heading to Tools -> Add-ons -> Plugins, while in Chrome just type about:plugins into the address bar. For Internet explorer 9 users should be able to go to Tools -> Manage Add-ons and select All Add-ons from the drop down list under Show.

 

Source: Copyright © PC & Tech Authority. All rights reserved.

See more about:  ubisoft  |  security
 
 

Readers of this article also read...

Best Android apps this week 

Best Android apps this week

 
First Look: MSI Z87 Mpower MAX Motherboard 

First Look: MSI Z87 Mpower MAX Motherboard

 
Best iPhone apps this week 

Best iPhone apps this week

 
Aliens: Colonial Marines screenshots 

Aliens: Colonial Marines screenshots

 
Top 25 apps for Android tablets 

Top 25 apps for Android tablets

 
Latest articles on BIT Latest Articles from BIT
Federal Budget 2013: So what are you going to be required to pay?
15 May 2013
Opinion: Want a handy summary of the 2013 federal budget? Here is one by Newcastle accountants ...
Architects: another profession on the list of people using Evernote
10 May 2013
Yes, apparently the hugely popular Evernote note-syncing app is also being used by people who ...
In Brisbane? Setting up a business?
10 May 2013
Too embarrassed to ask even the most basic questions? Here's your chance to find out about ...
Worried about staff losing the office keys?
8 May 2013
Here's an interesting idea: a system which lets you assign a digital office "key" to your ...
Need a LOT more storage?
7 May 2013
Do you have multiple offices or servers? Are your systems requiring so much storage your IT ...

Latest Comments

Latest Poll

Which broadband network do you think is the best choice for Australia?



or View results
The Coalition's.
  19%
 
Labor's.
  63%
 
Screw this I'm going back to smoke signals and string on a can.
  18%
TOTAL VOTES: 1718

Vote now
Ads by Google

From our Partners

PC & Tech Authority Downloads