Another security flaw discovered last week during the Black Hat Security conference affects users playing Battlefield Play4Free on Windows XP and Windows 2003 systems.
This is the second such exploit found concerning EA during the conference, the first being a flaw in how Origin handles URIs.
The root cause was found to be in how Play4Free utilizes its update system. It essentially allows hackers to inject a bunch of variables into commands to override the whitelist protection. These attacks then run in a batch file the next time the system boots up. Given that support for Windows XP is ending in 2014, it's probably high time those users upgrade to an operating system that came out a bit more recently than almost 12 years ago.
(via Arstechnica)
The webpage used in the exploit opens the game on a victim's computer and instructs it to load a malicious "MOD" file used to customize game settings and features, according to a document the researchers published Friday. Using some nonstandard behavior of a programming interface version found only in older versions of Windows, the MOD file is able to upload a malicious batch file that will be executed the next time the computer is restarted. The technique is successful because it overrides a whitelist that's supposed to restrict the sites that are permitted to load the Play4Free game.
This is the second such exploit found concerning EA during the conference, the first being a flaw in how Origin handles URIs.
The root cause was found to be in how Play4Free utilizes its update system. It essentially allows hackers to inject a bunch of variables into commands to override the whitelist protection. These attacks then run in a batch file the next time the system boots up. Given that support for Windows XP is ending in 2014, it's probably high time those users upgrade to an operating system that came out a bit more recently than almost 12 years ago.
(via Arstechnica)
