Description
Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local users to gain privileges via a Trojan horse file.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/33961
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/show/osvdb/108726
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/33961
Third Party Advisory x_refsource_misc
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5191.php
Scores
EPSS
0.0107
EPSS Percentile
77.8%
Details
CWE
CWE-264
Status
published
Products (2)
ubi/uplay_pc
4.5.2.3010
ubi/uplay_pc
< 4.6.3208
Published
Aug 25, 2014
Tracked Since
Feb 18, 2026