Home » News » Vulnerability in EA Origin client allows intruders to control gamers’ PCs

Vulnerability in EA Origin client allows intruders to control gamers’ PCs

For convenience of millions of users Origin supports URL that begins with «origin://».

Such links make possible to open application quickly and download a game, following a simple link from the website.

Researchers of Undergo Security found that using this bag intruders could make links “origin://../malware”, that would enable attackers to use any application with the rights of current user.

“An attacker could’ve ran anything they wanted,” – argue Underdog Security experts.

Specialists explain that potential cybercriminals could also transit PowerShell commands to vulnerable PC, in this way loading in system additional malware and installing it.

Malware origin:// link could be sent user in a letter or published on intruders’ web-page. In combination with XSS-vulnerability exploit could also work independently, without victim’s participation.

Moreover, bug allowed abduction of tokens from users’ accounts with the use of simple one-line code. As a result, criminals got access to user’s account without a password.

Origin EA Vulnerability
‘Popping calc’ to demonstrate a remote code execution bug in Origin

EA developers already eliminated this problem; update for vulnerability issued on Monday, April 15, 2019.

Source: https://techcrunch.com

[Total: 1    Average: 5/5]
READ  Alpine’s Docker-images were supplied with empty password of “root” user

About Trojan Killer

Carry Trojan Killer Portable on your memory stick. Be sure that you’re able to help your PC resist any cyber threats wherever you go.

Check Also

comodo ca

Great part of malware on VirusTotal had Comodo certificate

Comodo center of certification (known now as Sectigo) released the greatest number of certificates that …

WannaCry laptop

Infected by WannyCry and MyDoom laptop costs more than $1 million

Infected by six famous malware programs laptop played out on a public auction. Historically these …

Leave a Reply