Ubisoft: We Didn't Install a Rootkit on Your PC
July 30, 2012 4:50 PM
But Ubisoft admits its code allows remotely controllable arbitrary executable launches
defines a "
" as "a stealthy type of malicious software designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer."
We just heard back from a spokesperson from Ubisoft Entertainment S.A. (
) regarding claims that dozens of its most popular titles contained
a browser plugin that acted as a rootkit
There was some skepticism among readers regarding whether this was a true "rootkit". Writes
, "The described behavior of the DRM package doesn't define a rootkit at all. It may be an evil nonetheless, but let's be accurate here instead of using the R-word to inflame people by misdirection."
But it appears as more details have become available that the software was acting relatively close to the aforementioned definition of a rootkit, though it's likely closer to an unintentional Trojan by definition.
According to the Ubisoft spokesperson:
The browser plugin that we used to launch the application through Uplay was able to take command line arguments that developers used to launch their games while they're being made. This weakness could allow the application to specify any executable to run, rather than just a game. This means it was possible to launch another program on the machine.
Pre-patch the uPlay browser plug-in could allow remotely controlled arbitrary executable launch.
[Image Source: Geek.com]
Now Ubisoft denies that this is a rootkit, writing, "The Uplay application has never included a rootkit."
Technically this appears to be correct in that the plugin was not
to be malicious, and has not yet been exploited in the wild.
That said consider the following:
The browser plugin is intended to launch game related software, but due to apparent coding error is allowed unrestricted executable access, meaning its advertised purpose does not match its capabilities.
This makes it, in effect, an accidental Trojan.
The plugin allows privileged access to the host machine.
The plugin runs in the background and is largely invisible.
The plugin accepts remote control signals to control the host machine.
Thus even if Ubisoft is correct -- that Uplay is not acting as a rootkit at present -- if the control channel were to be hijacked by a third party, it would become one. Channel hijacking would fulfill the sole missing criteria -- malicious behavior.
In other words, Ubisoft is arguing semantics, but based on a purely technical standpoint its plugin is very close to being capable of offering similar capabilities to a rootkit if hijacked by a malicious party. That, ostensibly, is where various media reports labelling the plugin as a "rootkit" arose.
Semantics aside, Ubisoft appears to realize this is a dangerous capability to leave lying around. It writes:
The issue was brought to our attention early Monday morning and we had a fix into our QC department an hour and a half later. An automatic patch was launched that fixes the browser plugin so that it will only open the Uplay application. Ubisoft takes security issues very seriously, and we will continue to monitor all reports of vulnerabilities within our software and take swift action to resolve such issues.
To update your Uplay client and apply the patch:
-Close any open web browsers (Internet Explorer, Firefox, Chrome, Opera, etc.) If the web browser is open during the patch it will require restarting the browser.
-Launch the Uplay PC client. The Uplay PC client update will start automatically.
-An updated version of the Uplay PC installer is also available to download from Uplay.com.
It remains to be seen if this is enough to wash Ubisoft's hands of
liability for allowing arbitrary code execution
on victim machines.
"It's okay. The scenarios aren't that clear. But it's good looking. [Steve Jobs] does good design, and [the iPad] is absolutely a good example of that." -- Bill Gates on the Apple iPad
Ubisoft Caught Installing Exploitable DRM Plug-in on Users' Machines
July 30, 2012, 11:44 AM
The EFF Wants You to Know About Sony BMG Settlement
March 13, 2006, 2:17 AM
WhatsUp with WhatsApp?
August 29, 2016, 5:23 AM
Fuchsia – Google’s New Open Source Operating System
August 17, 2016, 6:30 AM
Windows 10: End of an Era & A New Beginning
August 1, 2016, 9:59 AM
Free Windows 10 offer ends July 29th, 2016: 10 Reasons to Upgrade Immediately
July 22, 2016, 9:19 PM
Quick Note: Whoops, Microsoft Pushed Unwanted Windows 10 to Some Users
October 15, 2015, 9:04 PM
Quick Note: Windows 10 Insider Preview Build 10565 Fixes Boot Camp 6.0 Issues
October 13, 2015, 11:39 AM
Most Popular Articles
What Can You Do with Your New Echo Dot?
December 3, 2016, 5:00 AM
Google has developed Deep Learning Algorithm to detect Diabetic Eye Disease
December 4, 2016, 5:00 AM
Foscam R2 Home Security Camera System – High Quality High FHD Security Video Footage with No Monthly Fees
December 1, 2016, 2:00 AM
The iPlugmate is an Excellent iPhone Flash Drive at a Great Price. (Deal Expires in 3 Days)
November 23, 2016, 1:00 AM
Microsoft Surface – Which Surface is Right for You?
December 2, 2016, 5:00 AM
Latest Blog Posts
In The News
Dec 7, 2016, 5:00 AM
e Guide: Mobile Security for 2017
Dec 6, 2016, 5:00 AM
Apple Car is Not Dead
Dec 5, 2016, 1:00 AM
Dec 4, 2016, 5:00 AM
Dec 3, 2016, 5:00 AM
Dec 2, 2016, 5:00 AM
Surface Ergonomic Keyboard
Dec 1, 2016, 3:01 AM
Chapeconense plane crash: Football rallies around Brazilian Team
Nov 30, 2016, 1:00 AM
How to Extends Your iPhone’s Battery Life
Nov 29, 2016, 12:49 AM
Nov 28, 2016, 1:12 AM
News: Fidel Castro
Nov 27, 2016, 5:00 AM
Nov 26, 2016, 5:00 AM
Changes in Social status affect the way genes turn on and off within immune cells.
Nov 25, 2016, 5:12 AM
Austrian far–right hopeful Hofer may back EU vote.
Nov 24, 2016, 4:00 AM
Final Fantasy XV Leaked Before Nov 29 Launch Date
Nov 23, 2016, 1:00 AM
Nov 22, 2016, 2:26 AM
Nov 21, 2016, 1:00 AM
HTC Makes Big Moves in China
Nov 20, 2016, 2:00 AM
Do you know who is the number one company in the word?
Nov 19, 2016, 5:30 AM
Foldable Cardboard ”EcoHelmet” wins James Dyson Award’s Top Prize
Nov 18, 2016, 2:39 AM
Scientists Discover Roundest Object Ever Spotted in Universe
Nov 17, 2016, 1:00 AM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information