正在加载视频...
视频加载失败
Here is ENLBufferPwn (CVE ID pending), a severe vulnerability in many first party 3DS, Wii U and Switch games. It allows remote code execution in a victim console by just having an online game session with an attacker. Vulnerability report: 🧵(1/7)
590,834 次观看 • 3 年前 •via X (Twitter)
10 条评论

Combined with other OS exploits, this vulnerability could allow an attacker to achieve full console takeover, and steal sentitive information or take audio/video recordings. It has scored 9.8/10 (Critical) in the CVSS 3.1 calculator. (2/7)

Nintendo has been releasing patches for affected games during 2022. A list of games that are known to have had the vulnerability at some point can be found in the vulnerability report. (3/7)

The vulnerability was safely reported by @Pablomf6 Rambo6Glaz and @fishguy6564 independenly during 2021/2022 through Nintendo's HackerOne program. In my case (I found it in Mario Kart 7), I received a $1000 bounty. (4/7)

Also, I'd like to thank Nintendo for giving me the opportunity to collaborate in the finding and research of this vulnerability, and putting resources in fixing it in older titles. I hope these actions have helped create a safer online gaming environment. (5/7)

Note that this vuln was found by some hackers in Mario Kart 7, known as the "Mario Kart 7 RCE". However, nobody reported it (see it being used to open the home menu here . The vuln was fixed in the @Ctgp7 mod pack as soon as I was made aware of it. (6/7)

If you are a media reporter and have any questions, please don't hesitate to send me a message through DMs, and I'll try to reply to it as soon as possible. :) (7/7)

Extra: The vulnerability has been assigned CVE ID: CVE-2022-47949 and is no longer pending.

Ah, I guess that explains the update

Is this also possible on the iQue 3DS version? (That version was not updated)

Probably that game is still vulnerable, but since Nintendo already gave permission to disclose the vulnerability I doubt they are fixing it.
