Home » News » Vulnerability in EA Origin client allows intruders to control gamers’ PCs

Vulnerability in EA Origin client allows intruders to control gamers’ PCs

For convenience of millions of users Origin supports URL that begins with «origin://».

Such links make possible to open application quickly and download a game, following a simple link from the website.

Researchers of Undergo Security found that using this bag intruders could make links “origin://../malware”, that would enable attackers to use any application with the rights of current user.

“An attacker could’ve ran anything they wanted,” – argue Underdog Security experts.

Specialists explain that potential cybercriminals could also transit PowerShell commands to vulnerable PC, in this way loading in system additional malware and installing it.

Malware origin:// link could be sent user in a letter or published on intruders’ web-page. In combination with XSS-vulnerability exploit could also work independently, without victim’s participation.

Moreover, bug allowed abduction of tokens from users’ accounts with the use of simple one-line code. As a result, criminals got access to user’s account without a password.

Origin EA Vulnerability
‘Popping calc’ to demonstrate a remote code execution bug in Origin

EA developers already eliminated this problem; update for vulnerability issued on Monday, April 15, 2019.

Source: https://techcrunch.com

[Total: 1    Average: 5/5]
READ  Experts discovered a botnet that exploits ADB and SSH for infecting Android devices

About Trojan Killer

Carry Trojan Killer Portable on your memory stick. Be sure that you’re able to help your PC resist any cyber threats wherever you go.

Check Also

Trojan Bolik masks under NordVPN

Bank Bolik Trojan masks itself under NordVPN

Doctor Web experts warned that attackers use copies of popular services sites to distribute Bolik …

Tor DDoS Attacks are Cheap

DDoS attacks that slow Tor network performance are quite cheap

Experts from Georgetown University and the US Navy Research Laboratory presented an interesting report at …

Leave a Reply