Ubisoft’s Uplay DRM installs rootkit, leaves PC vulnerable to attack

30 July 2012

Another day, another DRM controversy – and today it’s allegations that Ubisoft’s Uplay DRM installs a rootkit that exposes your PC to browser-based intrusion. Or maybe it’s an Abstergo Industries plot.

The claims comes via white hat hacker, Tavis Ormandy, who published an exploit that allows remote control of any PC with Uplay installed.

“While on vacation recently I bought a video game called Assassin’s Creed Revelations,” he wrote over on goodie hacker news site, Seclists.

“I didn’t have much of a chance to play it, but it seems fun so far. However, I noticed the installation procedure creates a browser plugin for its accompanying Uplay launcher, which grants unexpectedly (at least to me) wide access to websites.”

Most of Ubisoft’s recent games require Uplay, including the Assassin’s Creed series and the new Tom Clancy’s Ghost Recon: Future Soldier.

According to security experts, though, it looks like the vulnerability may have been quite unintentional.

“Functionality in the Uplay browser extension, that normally enables games to be launched from a web browser, turns out can also be used to launch any other program on the system,” an anonymous expert told CVG.

“In the demonstration making its rounds on the internet, the code launched a calculator.”

Ubisoft has apparently declined comment, but probably because they’re too busy fixing it to answer the phone.

Source: CVG

Related Articles

Student arrested over Wii homebrew hack

Sony hackers plead guilty to attacks

Man jailed for hacking Call of Duty

How Sony plans to protect your PSN account

You have read 1 out of 5 free articles. Log in or register for unlimited access.
  1. Kromaswow
    31.07.2012 at 09:04

    They are just making it easier to choose piracy over anything else. True 95% effective DRM does not even require special programming. Just drop game prices you dumb idiots. All hail Gabe (There I said it now gimme my HL3 nom nom nom)

Read now

The best gaming website in South Africa
MyGaming proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to [email protected] Contact the Press Council on 011 4843612.