Feeds

Ubisoft assassinates Uplay flaw, denies DRM rootkit

Browser plugin allowed any file to execute

Securing Web Applications Made Simple and Scalable

A bit of holiday fun for Google security researcher Travis Ormandy left Ubisoft scrambling to fix a gaping flaw in its Uplay gaming application on Monday morning.

"While on vacation recently I bought a video game called 'Assassin's Creed Revelations,' he posted on the Full Disclosure mailing list. "I noticed the installation procedure creates a browser plugin for its accompanying Uplay launcher, which grants unexpectedly (at least to me) wide access to websites."

A demonstration page showed how a visitor's browser with the Uplay plugin installed could be made to launch a calculator application as a test case. The problem was initially reported as being a form of rootkit used for monitoring the Ubisoft's DRM system, but the company denied this in a statement to El Reg.

"The issue is not a rootkit. The Uplay application has never included a rootkit. The issue was from a browser plug-in that Uplay PC utilizes which suffered from a coding error that allowed systems usually used by Ubisoft PC game developers to make their games," it said.

The company said that it got the news of the flaw early on Monday morning and had a patch out within 90 minutes, giving a few people a very sudden start to the working week. Around 20 of its most recent games are thought to be vulnerable and Ubisoft advised users to download the patch, shut down all browsers, and run the update to fix the issue.

The rootkit row, although misguided, demonstrates the continuing frustration with some over Ubisoft's latest DRM system, which require some games to maintain a constant internet connection to function. While this is an effective form of DRM, it's cold comfort if your connection goes down seconds before you level up. ®

Mobile application security vulnerability report

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.