1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Web Attack: Ubisoft uplay CVE-2012-4177

Web Attack: Ubisoft uplay CVE-2012-4177

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

Ubisoft Uplay ActiveX Control is prone to a remote buffer-overflow vulnerability; fixes are available.

Additional Information

Ubisoft Uplay ActiveX Control is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds check user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition. Uplay 2.0.3 is vulnerable; other versions may also be affected.

Affected

  • Ubisoft uplay 2.0.3

Response

Updates are available; please see the references for more information.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube