Backdoor For Malware Discovered In Some Ubisoft Games [Updates]

Exploitable code has been discovered in a browser-plugin installed by some Ubisoft games as part of the Uplay service. The exploit allows malicious websites to remotely install software on a compromised PC without the user’s knowledge.

The exploit is accomplished by tricking the Uplay browser plugin into thinking that a given link contains legitimate Uplay code. In theory, this backdoor could be used to infect a computer with any malware desired. There’s no sign of a patch yet, so users need to look out!

Worse still, users who are vulnerable to this exploit may not even know a browser plug-in is installed. I personally fall into this category. Several days ago I installed a copy of Ghost Recon: Future Soldier. Ubisoft did not inform me that it had added a plug-in to my browser, so I was surprised to find that the vulnerable plug-in was installed.

The plug-in appears to install in all major browsers including Opera. You’ll need to go into your browser’s options to find and delete it. It always includes “Uplay” in its title, so it’s at least easy to find. Only Ubisoft games that require the Uplay service have this problem.

So far, there have not been any reported instances of the exploit being used in the wild. The discovery was publicized on Hacker News and has since been widely reported, so attempts to utilize it seem likely. Ubisoft has made an official announcement that informs players how they can fix the exploit.

Source: Rock, Paper, Shotgun

Matt Smith

Matthew Smith is a freelance writer living in Portland Oregon. He also writes for Digital Trends and runs a gaming blog called The Skill Point. You can follow him on Twitter or .

The comments were closed because the article is more than 180 days old.

If you have any questions related to stuff mentioned in the article or need help with any computer issue, just ask it on MakeUseOf Answers.

Hide 5 Comments

  • Igor Rizvi? July 31, 2012
    0 likes

    Wow i had the same addons,thx for posting this!!

    | Like
  • Jerick Dilla July 31, 2012
    0 likes

    Oh Ubisoft… Guess we have to watch out what things these game installations actually install so we can still ensure our safety.

    | Like
  • Alexander Zahn July 31, 2012
    0 likes

    Come on Ubisoft!

    | Like
  • sabih July 31, 2012
    0 likes

    I rarely play the current Ubisoft games. They need to fix this problem.

    | Like
  • Charlie Player August 2, 2012
    0 likes

    lol and poor ubisoft…

    | Like