Ubisoft Uplay 5.0 Insecure File Permissions Local Privilege Escalation

Uplay for PC suffers from an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘F’ flag (Full) for ‘Users’ group, making the entire directory ‘Ubisoft Game Launcher’ and its files and sub-dirs world-writable.

Leave a Reply