A Google security researcher has discovered a security flaw in the Blizzard Update Agent that ships with all of the company’s games. The vulnerability – known as “DNS Rebinding” – allows someone to send malicious files through the Update Agent after the server thinks they are game updates. The flaw was reported to Blizzard in early December 2017 by security researcher Tavis Ormandy.
According to a report published online explaining the vulnerability, the Blizzard Update Agent contains a JSON RPC server that other applications could send commands to and interact with. Ormandy discovered that he could use a browser to pass malicious JavaScript to a user via the server. To demonstrate his discovery, he published a POC (Proof Of Concept) page that performs DNS rebinding attacks against the Blizzard Agent, as well as another page that performs the same attack on other applications, so that security researchers can use them to find new applications vulnerable to this type of vulnerability.
Ormandy publicly revealed the bug on Twitter yesterday, also saying that Blizzard fixed the problem with a patch that was secretly pushed to its servers on December 22. The researcher also expressed his dissatisfaction after Blizzard refused to contact him to ask him further questions and disagreed with the way they fixed the vulnerability. Finally, he said that he plans to examine security flaws in known games and servers in the near future.

