Nintendo Has Been Patching A "Severe" Vulnerability Found In Some Online Switch, 3DS, And Wii U Games - Gaming News google.com, pub-1884294887586162, DIRECT, f08c47fec0942fa0
Gaming News
No Result
View All Result
  • PC
  • PlayStation
  • Xbox
  • Nintendo
  • Crypto Gaming
  • Reviews
  • Metaverse
  • Videos
  • PC
  • PlayStation
  • Xbox
  • Nintendo
  • Crypto Gaming
  • Reviews
  • Metaverse
  • Videos
No Result
View All Result
Gaming News
No Result
View All Result

Nintendo Has Been Patching A “Severe” Vulnerability Found In Some Online Switch, 3DS, And Wii U Games

March 3, 2023
in Featured News
0 0
0
2
VIEWS
Share on FacebookShare on Twitter


Switch
Image: Damien McFerran / Nintendo Life

Update [Fri 3rd Mar, 2023 15:30 GMT]: Nintendo has announced that it has begun temporary emergency maintenance on Splatoon and Mario Kart 8 for the Wii U.

While unconfirmed, it’s heavily speculated that the maintenance – which at the time of writing has no time frame attached to it – is linked to the ‘ENLBufferPwn’ exploit detailed in the article below.

As a quick reminder, the exploit effectively allows attackers to gain control of target Wii U and 3DS consoles by simply connecting to players online.

Hopefully the maintenance will prevent the exploit from being used in the future, however it’s currently unknown when exactly the online services for Splatoon and Mario Kart 8 will be back up and running.

Nintendo Maintenance
Image: Nintendo

Original Article [Wed 28th Dec, 2022 11:15 GMT]:

A severe vulnerability affecting several Nintendo consoles was found recently, with the potential to allow unauthorised access to Switch, 3DS, and Wii U via a host of online games. It’s reported that for some time Nintendo has been working to patch games to eliminate the exploit known as ‘ENLBufferPwn’, with several updates already live to address the situation (thanks, Nintendo Everything).

The vulnerability, which has been categorised as ‘Critical’ on the Common Vulnerability Scoring System (CVSS) and detailed in full on GitHub by PabloMK7, Rambo6Glaz, and Fishguy6564, reportedly exposes a victim’s device to complete remote control by simply playing an online game with a potential attacker. This means that attackers may gain access to sensitive information or take audio and video recordings by remotely executing code.

The vulnerability was reported to Nintendo in “2021/2022” by @Pablomf6 — who says they received a $1000 “bounty” via Nintendo’s HackerOne program — and it is now understood that the company has taken action to fix the issue in some of the affected games, including Mario Kart 7, which was recently updated after more than a decade.

It seems most high-profile Switch titles have already been fixed, but it looks like Mario Kart 8 and Splatoon on Wii U have yet to be addressed and may still be affected by the vulnerability.

Here’s a list of affected titles, as per the GitHub page:

It’s speculated that other games may also be affected by the vulnerability, although that’s unconfirmed at present.

For a look at the exploit in action, take a peek at the below video from PabloMK7 which demonstrates an attacker (left console) remotely taking over an unmodified 3DS (right side) by copying a return-oriented programming (ROP) payload and executing it remotely. The victim console is then forced to run a custom firmware installer and it’s thought that the same technique would allow an attacker to steal sensitive information from a remote console. Thankfully, this has now been fixed and can no longer be carried out if you’re running the latest version of the software, so be sure to update if you haven’t!

Subscribe to Nintendo Life on YouTube

Nintendo’s relatively limited approach to online play seems to have its advantages when it comes to security issues like this, as pointed out by @LuigiBlood discussing the exploit:

Unless Nintendo gave their network library (Not NEX!) to some external devs like Camelot, Arika and Bandai Namco which I very highly doubt, I think Wii U and 3DS online will still be around for a while.
At worst they could just cut online for these games only.
— Yakumono (@LuigiBlood) December 24, 2022

Those two games mentioned are Mario Kart 8 and Splatoon, so if you still play either of those titles online on your Wii U, we recommend exercising extreme caution or avoiding them altogether until more information is available. We’ll update this article if further details come to light.

What do you make of this? Share your thoughts in the comments below.





Source link

Previous Post

SpongeBob SquarePants: The Cosmic Shake – Release Trailer | PS4 Games

Next Post

FOX Renews Dan Harmon’s Krapopolis for a Third Season Before Season 1 Airs!

Next Post
FOX Renews Dan Harmon’s Krapopolis for a Third Season Before Season 1 Airs!

FOX Renews Dan Harmon’s Krapopolis for a Third Season Before Season 1 Airs!

Recommended

Meilleur On line casino en Ligne au Canada en argent réel 2026

June 3, 2026

Yep On line casino Polska Rodzaje bonusw i nagrd dla graczy on-line.766

June 3, 2026

On line casino Spinsy en France information complet des jeux et fonctionnalits du on line casino.1269

June 3, 2026

Desentrañando el misterio y la fortuna de joker jewels con cada giro

June 3, 2026

Gaming News

Get latest Gaming News on Pley2win.com. Popular Games, New released, Gaming Review, Xbox gaming, PlayStation, PC, Mobile Gaming and More!!

Categories

  • ! Valorant Boosting Tips
  • ! Без рубрики
  • 1
  • 10
  • 1000A Z
  • 1090A Z
  • 111
  • 18.12.1
  • 1win-np.com
  • 1xbetapp-ph.com3
  • 2000A Z
  • 237-Spassino Casino
  • 274 BeepBeep Casino –
  • 3
  • 318 Wizebets Italy
  • 4
  • 44
  • 5
  • 50%A 50 Z
  • 50%A 50B Z
  • 507-Pelican Casino
  • 777casino
  • 8
  • 800A 200BA Z
  • a16z generative ai
  • adobe generative ai 3
  • adobe generative ai 8
  • Article
  • Avocasino
  • bahisyasal 4521
  • Blog
  • Bookkeeping
  • Boomerang Casino
  • BT prod 5715
  • Business, Small Business
  • Casino
  • Casino De Arturo
  • casinocatspins
  • casinopinco
  • casinowazamba
  • catspinscasino
  • CH
  • Chicken Road rules
  • chickenroad
  • CIB
  • Computers, Games
  • cresuscasino
  • Crypto Gaming
  • de
  • dec_bh_common
  • dec_bh_main
  • dec_pb_common
  • December
  • dushscience.in
  • EC
  • edeka-halmschlag.de
  • Efbet Jackpots
  • Featured News
  • FinTech
  • first
  • Forex News
  • Forex Trading
  • Games
  • Gaming News
  • generative ai adobe photoshop 3
  • ghostinocasino
  • giochi
  • gokspel
  • hautarzt-rw.de
  • impressariocasino
  • jan4
  • jeux
  • jeuxi
  • Leon Casino
  • Leonbet
  • Live
  • Live Στοίχημα
  • lobby303sky.info
  • madnixcasino
  • Metaverse
  • Mobile Στοίχημα
  • mostbet
  • NEW
  • New Released
  • News
  • ninecasino
  • Nintendo
  • nko-zdrav.ru
  • nov2
  • nov6
  • novos-casinos
  • Online Casino
  • online καζίνο
  • PC
  • pinco
  • platinumslotscasino
  • PlayStation
  • Plinko
  • Plinko Online Casino
  • Popular
  • Post
  • Public
  • ready_text
  • Reviews
  • Rolldorado
  • rubds1010.ru 10
  • sep
  • Sex
  • Sober living
  • spel
  • Spellen
  • spiderbetscasino
  • Spiele
  • spiller1
  • Sport
  • Stake
  • tenexcasino
  • test
  • Trading
  • trends
  • Uncategorized
  • VeryWell Casino
  • Videos
  • voxcasino
  • vrclub-tron.ru 10
  • vulkanvegascasino
  • what to name your ai
  • Wildrobin
  • wildz
  • wildzcasino
  • www.xin-chao.de
  • Xbox
  • zuplay-in.com2
  • Αθλητικά Στοιχήματα
  • Καζίνο
  • Φρουτάκια
  • Блог
  • Новости Криптовалют
  • Текста
  • Финтех
  • Форекс Брокеры56

Follow us

  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2022 - Pley 2 Win.

No Result
View All Result
  • PC
  • PlayStation
  • Xbox
  • Nintendo
  • Crypto Gaming
  • Reviews
  • Metaverse
  • Videos

Copyright © 2022 - Pley 2 Win.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.