Origin exploit discovered, allows EA store to launch malicious code

V_R

¯\_(ツ)_/¯
Moderator
Joined
Jan 31, 2005
Messages
13,572
Reaction score
1,888
EA's online game store Origin has been hacked to run malicious code. The exploit was discovered by third-party security company ReVuln while running tests on the software.
It allows a malicious user to swap links that launch already-downloaded games with those for alternatives.
There's no evidence the loophole has yet been identified or exploited by anyone else, BBC News reported.
"The Origin platform allows malicious users to exploit local vulnerabilities or features by abusing the Origin URI handling mechanism," ReVuln researchers Donato Ferrante and Luigi Auriemma wrote in a paper identifying the issue.

"In other words, an attacker can craft a malicious internet link to execute malicious code remotely on [a] victim's system, which has Origin installed."
ReVuln has published a more detailed explanation of how someone could manipulate the code, along with information on what EA should do to combat it.
In the meantime, players can avoid the issue by only launching Origin games directly through the service, rather than via desktop shortcuts.
EA has said it is "investigating" the vulnerability.
News of the security thread comes at a torrid time for EA. Company boss John Riccitiello announced his departure last night after weaker-than-expected financial results and a fortnight of embarrassment surrounding the launch of SimCity.
http://www.eurogamer.net/articles/2...ered-allows-ea-store-to-launch-malicious-code

:rolleyes:

Luckily, I only play BF3 via Origin so i use Battlelog. I hate desktop shortcuts!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top