Check Point Reference: | CPAI-2013-1317 |
Date Published: | 25 Feb 2013 |
Severity: | Critical |
Last Updated: | Thursday 09 January, 2025 |
Source: | CVE-2012-4177 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Ubisoft Uplay 2.0-2.0.3 |
Vulnerability Description | A remote code execution vulnerability exists in Ubisoft Uplay 2.0.3. The vulnerability is due to insufficient verification of a command path parameter value when parsing a Uplay ActiveX object. A remote attacker can exploit this vulnerability by enticing a user to open a webpage that contains a specially crafted Uplay ActiveX object with a specific orbit_exe_path parameter value. |
The protection will stop attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Web Client Enforcement Violation
Attack Information: Ubisoft Uplay 2.0.3 ActiveX Control Arbitrary Code Execution