Skip to: Site Navigation | Search | Content

Legit Reviews

Product Reviews - Industry Facts - Technology Issues

Legit News

Ubisoft's Intrusive DRM Creates Significant Security Hole

Certain Ubisoft games install a browser plug-in as part of their DRM infrastructure, which can lead to drive-by attacks from infected or malicious websites, create a significant security hole.

Ubisoft's DRM infrastructure means that certain games such as Assassin's Creed II and Tom Clancy's H.A.W.X. 2 silently install a plug-in from Uplay in web browsers such as Firefox, Chrome, Opera and IE. This has the unintended consequence of allowing drive-by attacks from any website, allowing any action to be taken on a PC, potentially putting under the complete control of an attacker. It appears that the flaw may have been patched now, but it's not certain as of the time of writing. There's a proof of concept exploit here which starts the calculator. The good news is that removing the plug-in from the browser removes the vulnerability, so it's easily fixed. There's another way to fix this of course: don't buy Ubisoft titles, since it only encourages them to use this kind of intrusive and dangerous DRM, which many other companies avoid. Dropping sales will soon show them the error of their ways.

We've tested with a PC that has never had Uplay installed on it. The exploit didn’t work at all. After installing Uplay alone, immediately the test link did indeed work, calling up the Uplay window, and then with that, booting the Windows Calculator. After uninstalling Uplay, the exploit once again didn't work.

Rock, Paper, Shotgun

Posted by | Mon, Jul 30, 2012 - 04:22 PM


blog comments powered by Disqus

Recent Articles
  • MSI Z77A-GD65 Gaming Series Motherboard Review
  • ASUS Xonar DGX and Xonar DSX Audio Cards Reviews
  • WD My Passport Ultra 1TB Storage Drive Review
  • ASUS PCE-AC66 Dual-Band 802.11 AC PCIe Wireless Card Review
  • Kingston MobileLite Wireless Card Reader Review
  • Seagate Desktop HDD.15 4TB vs WD Black 4TB Hard Drive Review
  • Kingston DataTraveler Ultimate 3.0 G3 32GB Flash Drive Review
  • Buffalo AirStation N600 Dual-Band Wireless Router Review
  • Be Quiet! Dark Power Pro 10 850W BN603 PSU Review
  • ASUS VivoTab Smart ME400 10.1 inch Windows 8 Tablet Review
Recent News
  • GeLid Launches Rev. 2 GX-7 GAMER CPU Cooler
  • Minuteman III Test Launch Scheduled By US Air Force For Tomorrow
  • Yahoo! to Acquire Tumblr For $1.1 Billion
  • Sony PlayStation 4 Will Be Shown At E3 - Teaser Trailer Released
  • EVGA ACX GPU Cooler Trailer Released - GeForce GTX 700 Series GPU Cooler
  • Futuremark Announces PCMark 8 Benchmark Coming in Q2
  • Samsung Launches New NFC Tags - TecTiles 2
  • Razer Releases Atrox Arcade Stick for Xbox 360
  • Lenovo Launches Yoga 11S Convertible PC - Starting at $800
  • ADATA Announces DashDrive Choice UC510 Flash Drive Series

Socialize

  • Facebook
  • Twitter
  • YouTube

Search

Hot Topics

  • 42" Panasonic Viera 1080p LED HDTV for $374 Shipped
  • GeLid Launches Rev. 2 GX-7 GAMER CPU Cooler
  • Spring Cleaning - Ah Nastalgia...
  • Yahoo! to Acquire Tumblr
  • Announcing PCMark 8, includes new battery tests & more
  • MSI Z77A-GD65 Gaming Series Motherboard Review
  • Just wondering
  • ASUS Xonar DGX and Xonar DSX Audio Cards Reviews
  • RAZER LAUNCHES ATROX ARCADE STICK
  • Lenovo Launches Yoga 11S Convertible PC

Explore ::

  • News
  • Articles
  • Editorial
  • Interviews
  • Events
  • Folding
  • Forums

Content ::

  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • Bluetooth
  • Cooling
  • Miscellaneous

About ::

  • Contact
  • About Us
  • Disclaimer

Copyright © 2002-2013 Legit Reviews™ & LegitReviews.com - All Rights Reserved.

  • Home
  • Forums
  • Favorite
  • RSS Feeds
  • Shopping
  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • PC Cases
  • Cooling
  • Misc