Ubisoft’s Uplay DRM installs rootkit, leaves PC vulnerable to attack

White hat hacker exposes Uplay security risk

July 30, 2012
uplay hacked header

Another day, another DRM controversy – and today it’s allegations that Ubisoft’s Uplay DRM installs a rootkit that exposes your PC to browser-based intrusion. Or maybe it’s an Abstergo Industries plot.

The claims comes via white hat hacker, Tavis Ormandy, who published an exploit that allows remote control of any PC with Uplay installed.

“While on vacation recently I bought a video game called Assassin’s Creed Revelations,” he wrote over on goodie hacker news site, Seclists.

“I didn’t have much of a chance to play it, but it seems fun so far. However, I noticed the installation procedure creates a browser plugin for its accompanying Uplay launcher, which grants unexpectedly (at least to me) wide access to websites.”

Most of Ubisoft’s recent games require Uplay, including the Assassin’s Creed series and the new Tom Clancy’s Ghost Recon: Future Soldier.

According to security experts, though, it looks like the vulnerability may have been quite unintentional.

“Functionality in the Uplay browser extension, that normally enables games to be launched from a web browser, turns out can also be used to launch any other program on the system,” an anonymous expert told CVG.

“In the demonstration making its rounds on the internet, the code launched a calculator.”

Ubisoft has apparently declined comment, but probably because they’re too busy fixing it to answer the phone.

Source: CVG

Related Articles

Student arrested over Wii homebrew hack

Sony hackers plead guilty to attacks

Man jailed for hacking Call of Duty

How Sony plans to protect your PSN account

Tags: active, Hack, Megarom, rootkit, security hack, ubisoft, uplay

Poll

Are you interested in the SA gaming clan scene?

View Results

Loading ... Loading ...

Latest News

Awesome game trailers this week

gaming video roundup

Catch up with all the big game trailers this week

MyGaming Dota 2 Season 3 sponsored by Cooler Master

MyG DOTA 2 SECS season 3

Registrations are live and battles kick off this Sunday!

Internet Explorer 10 declared “internet’s safest browser”

Hacker header

Protected users from the most malware downloads in a NSS Labs study.

ASRock Haswell HDMI Pass-thru adds flexibility to gaming battle stations

ASRock OC Formula header

Plug in your tablet or PS Vita and have video output on your PC monitor.

bool(true)