HomeSecurityCall of Duty players hack other players via RCE vulnerability

Call of Duty players are hacking other players via RCE vulnerability

Call of Duty: WWII has been pulled from PC following reports of a serious remote code execution (RCE) vulnerability that allowed malicious players to gain complete control over other players' computers during online multiplayer matches.

See also: Countdown to the new Call of Duty: Black Ops 6! When will it be released?

Call of Duty RCE

On Saturday, the Call of Duty development team announced that the PC version of Call of Duty: WWII had been taken offline, following "reports of an issue."

What initially seemed like a routine technical glitch turned out to be a critical security vulnerability that put thousands of PC gamers at risk. The issue involved an RCE exploit that allowed attackers to execute malicious code on victims’ computers without their consent or physical access. The vulnerability became even more concerning just days after the 2017 title joined Microsoft’s Game Pass service, following Microsoft’s acquisition of Activision in 2023.

Reports from affected players paint a disturbing picture of the exploit's capabilities. During live multiplayer matches, malicious users were able to gain remote access to other players' computers and perform a range of intrusive actions.

See also: Sloclap presents “Rematch” at The Game Awards 2024

Victims reported that attackers opened command prompt windows on their computers, sent sarcastic messages via Notepad, caused remote system shutdowns, and even changed desktop wallpapers with inappropriate content.

Call of Duty Xbox
Call of Duty players are hacking other players via RCE vulnerability

The vulnerability exclusively affects gamers using Windows, as consoles generally do not allow such a level of code execution.

This technical limitation means that only players who accessed the game through platforms like Game Pass and possibly Steam were at risk.

The root of the problem appears to lie in Call of Duty: WWII's reliance on peer-to-peer (P2P) networking for its multiplayer matches.

In this system, a player's computer functions as a server (server) for the entire match, creating possible entry points for malicious users who can exploit vulnerabilities in the systems of the other players.

See also: FTC: Withdraws from Activision Blizzard acquisition case by Microsoft

This security flaw comes as no surprise to the Call of Duty community, where hacking older titles is now almost an “open secret.” Many seasoned gamers have long avoided playing older versions of Call of Duty on Steam due to security concerns.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS