正在加载视频...

视频加载失败

Here is ENLBufferPwn (CVE ID pending), a severe vulnerability in many first party 3DS, Wii U and Switch games. It allows remote code execution in a victim console by just having an online game session with an attacker. Vulnerability report: 🧵(1/7)

590,834 次观看 • 3 年前 •via X (Twitter)

10 条评论

PabloMK7 的头像
PabloMK73 年前

Combined with other OS exploits, this vulnerability could allow an attacker to achieve full console takeover, and steal sentitive information or take audio/video recordings. It has scored 9.8/10 (Critical) in the CVSS 3.1 calculator. (2/7)

PabloMK7 的头像
PabloMK73 年前

Nintendo has been releasing patches for affected games during 2022. A list of games that are known to have had the vulnerability at some point can be found in the vulnerability report. (3/7)

PabloMK7 的头像
PabloMK73 年前

The vulnerability was safely reported by @Pablomf6 Rambo6Glaz and @fishguy6564 independenly during 2021/2022 through Nintendo's HackerOne program. In my case (I found it in Mario Kart 7), I received a $1000 bounty. (4/7)

PabloMK7 的头像
PabloMK73 年前

Also, I'd like to thank Nintendo for giving me the opportunity to collaborate in the finding and research of this vulnerability, and putting resources in fixing it in older titles. I hope these actions have helped create a safer online gaming environment. (5/7)

PabloMK7 的头像
PabloMK73 年前

Note that this vuln was found by some hackers in Mario Kart 7, known as the "Mario Kart 7 RCE". However, nobody reported it (see it being used to open the home menu here . The vuln was fixed in the @Ctgp7 mod pack as soon as I was made aware of it. (6/7)

PabloMK7 的头像
PabloMK73 年前

If you are a media reporter and have any questions, please don't hesitate to send me a message through DMs, and I'll try to reply to it as soon as possible. :) (7/7)

PabloMK7 的头像
PabloMK73 年前

Extra: The vulnerability has been assigned CVE ID: CVE-2022-47949 and is no longer pending.

EC2★Marito_yo🏳️‍🌈‍  的头像
EC2★Marito_yo🏳️‍🌈‍ 3 年前

Ah, I guess that explains the update

lunacaoimhe.bsky.social 的头像
lunacaoimhe.bsky.social3 年前

Is this also possible on the iQue 3DS version? (That version was not updated)

PabloMK7 的头像
PabloMK73 年前

Probably that game is still vulnerable, but since Nintendo already gave permission to disclose the vulnerability I doubt they are fixing it.

相关视频