In January, Google Project Zero researcher Tavis Ormandy revealed a vulnerability in the BitTorrent app, explaining that a similar problem could exist elsewhere.
In a new report this week, Ormandy reveals a similar security vulnerability in uTorrent. The issue was reported to BitTorrent in November, but as the security researcher predicted, the parent company failed to issue a patch within the 90-day window recommended to fix the bugs found as part of Project Zero this week.
The flaw exists in the web interface that allows users to remotely control the BitTorrent program and, if exploited, could allow an attacker to take control of the vulnerable computer.
The developer, however, says it has already prepared an updated version that is currently available as part of the latest beta and according to a report from TorrentFreak, it is expected to be pushed to the stable channel this week.
But as it turns out, the patch, which has been published by Ormandy, simply renders the update useless, since it does not fix the vulnerability.
“It appears BitTorrent just added a second token to uTorrent Web. This does not resolve the DNS reconnection issue,” Ormandy explained on Twitter. “The exploit has just been fixed and confirmed to still work. I would recommend asking BitTorrent to resolve this issue if you are affected, and since it works in the default configuration you most likely are.”
BitTorrent hasn't released an updated statement to share new details about how and when it plans to ship a new patch, but with the vulnerability information now public, the company should do so as soon as possible. The last update to uTorrent was released on February 17th to version 3.5.3 Build 44352 Beta. The most recent stable update is dated December 24th – version 3.5.1.

