Home / Software & Gaming / Ubisoft uPlay has big vulnerability

Ubisoft uPlay has big vulnerability

Ubisoft's online service, uPlay, has had a real vulnerability exposed, that can be used to view customer files and information.

While it was initially thought that this was a deliberate backdoor hidden by programmers of the service, it seems more likely now that it is an unintentional vulnerability. IT “experts” speaking with CVG, said that: “Functionality in the uPlay browser extension, that normally enables games to be launched from a web browser, turns out can also be used to launch any other program on the system.”

“In the demonstration making its rounds on the internet, the code launched a calculator.”

uPlay
uPlay, how about uFix this Ubisoft?

While this might not have been a big problem if uPlay was voluntary, the fact that it was designed as a DRM system to protect the company's games and is therefore mandatory, makes it a real issue. Gamers are being forced to install software that is inherantly insecure and potentially provides hackers with a loophole.

“I noticed the uPlay installation procedure creates a browser plugin for its accompanying uPlay launcher, which grants unexpectedly (at least to me) wide access to websites,” said one hacker on the Ycominator forum, when discussing the vulnerability.

KitGuru Says: Ubisoft will need to jump on this in some official manner if it doesn't want to risk alienating consumers and its player base.

Become a Patron!

Check Also

Chinese Steam

Hidden Steam Support page lets you see your lifetime spend on games

Steam has grown from strength to strength since launching in the mid 2000s, building up …

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!