Researchers of Undergo Security found that using this bag intruders could make links “origin://../malware”, that would enable attackers to use any application with the rights of current user.
“An attacker could’ve ran anything they wanted,” – argue Underdog Security experts.
Specialists explain that potential cybercriminals could also transit PowerShell commands to vulnerable PC, in this way loading in system additional malware and installing it.
Malware origin:// link could be sent user in a letter or published on intruders’ web-page. In combination with XSS-vulnerability exploit could also work independently, without victim’s participation.
Moreover, bug allowed abduction of tokens from users’ accounts with the use of simple one-line code. As a result, criminals got access to user’s account without a password.
‘Popping calc’ to demonstrate a remote code execution bug in Origin
EA developers already eliminated this problem; update for vulnerability issued on Monday, April 15, 2019.
Source: https://techcrunch.com
About Re-captha-version-4-21.buzz Re-captha-version-4-21.buzz pop-ups can not launch out of the blue. If you have actually…
About Eliteadblocker.net Eliteadblocker.net pop-ups can not expose out of the blue. If you have clicked…
About News-xzexivu.info News-xzexivu.info pop-ups can not introduce out of the blue. If you have actually…
About Linkbtrads.top Linkbtrads.top pop-ups can not expose out of nowhere. If you have actually clicked…
About News-xzekevu.xyz News-xzekevu.xyz pop-ups can not introduce out of the blue. If you have actually…
About News-xzurufo.xyz News-xzurufo.xyz pop-ups can not introduce out of the blue. If you have clicked…