HomeinetBlizzard fixed a vulnerability that was not known to the general public

Blizzard fixed a vulnerability that was not known to the general public

A Google security researcher has discovered a security flaw in the Blizzard Update Agent that ships with all of the company’s games. The vulnerability – known as “DNS Rebinding” – allows someone to send malicious files through the Update Agent after the server thinks they are game updates. The flaw was reported to Blizzard in early December 2017 by security researcher Tavis Ormandy.

Blizzard

According to a report published online explaining the vulnerability, the Blizzard Update Agent contains a JSON RPC server that other applications could send commands to and interact with. Ormandy discovered that he could use a browser to pass malicious JavaScript to a user via the server. To demonstrate his discovery, he published a POC (Proof Of Concept) page  that performs DNS rebinding attacks against the Blizzard Agent, as well as another page that performs the same attack on other applications, so that security researchers can use them to find new applications vulnerable to this type of vulnerability.

Ormandy publicly revealed the bug on Twitter yesterday, also saying that Blizzard fixed the problem with a patch that was secretly pushed to its servers on December 22. The researcher also expressed his dissatisfaction after Blizzard refused to contact him to ask him further questions and disagreed with the way they fixed the vulnerability. Finally, he said that he plans to examine security flaws in known games and servers in the near future.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS