CVE-2012-4177
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- http://forums.ubi.com/showthread.php/699940-Uplay-PC-Patch-2-0-4-Security-fix
- http://osvdb.org/84402
- http://seclists.org/fulldisclosure/2012/Jul/375
- http://www.bbc.com/news/technology-19053453
- http://www.exploit-db.com/exploits/20321
- http://forums.ubi.com/showthread.php/699940-Uplay-PC-Patch-2-0-4-Security-fix
- http://osvdb.org/84402
- http://seclists.org/fulldisclosure/2012/Jul/375
- http://www.bbc.com/news/technology-19053453
- http://www.exploit-db.com/exploits/20321
CWEs
CWE-78
Verify integrity in audit chain (admin only). AS-IS.