Call of Duty: WW2 hacked, causing damage such as 'launching Notepad,' 'forced PC shutdown,' and 'displaying the lawyer's face'



A few days after Call of Duty: WW2 was added to Microsoft's fixed-fee gaming service PC Game Pass , the game was removed from distribution due to a series of reports of hacking from users. The damage appears to be limited to PC Game Pass users.

Call of Duty: WW2 pulled from PC following reports of remote code exploit trolling players with 'Notepad pop-ups, PC shutdowns' and desktop wallpaper of a lawyer | PC Gamer
https://www.pcgamer.com/games/call-of-duty/call-of-duty-ww2-pulled-from-pc-following-reports-of-remote-code-exploit-trolling-players-with-notepad-pop-ups-pc-shutdowns-and-desktop-wallpaper-of-a-lawyer/

Call Of Duty: WWII's Game Pass PC Version Was Pulled, Reportedly After Hacking Issues - GameSpot
https://www.gamespot.com/articles/call-of-duty-wwiis-game-pass-pc-version-was-pulled-reportedly-after-hacking-issues/1100-6532997/

The latest hack reportedly involved a remote code execution (RCE) attack that allowed unauthorized code to be executed on users' PCs.

Victims were shown random pornographic content, had Notepad launched without their permission and shown messages, and had a lawyer's photo set as their desktop wallpaper without their permission.




The lawyer used in the wallpaper was Mark Mayer, the same lawyer hired by Activision, the developer of Call of Duty: WW2, in their lawsuit against cheat-selling companies.




According to users who purchased this hacking tool, in addition to RCE attacks, the tool also contained the ability to arbitrarily ban players from the game and enable a 'god mode' that makes players infinitely stronger.

Activision immediately suspended distribution of Call of Duty: WW2 after receiving the reports, but did not comment on whether these issues were the result of an RCE attack, simply stating that they had suspended online services to investigate 'issues.'




White hat hacker group VX-Underground warned, 'Fortunately, the attackers are only playing pranks, but RCE attacks can be used to inject malware that extracts information or install remote administration tools.'

This is not the first time that an RCE attack has been carried out through a game; a similar incident occurred in the past with Dark Souls III.

Dark Souls 3's 'PC takeover glitch' causes game server to be temporarily suspended, new game 'ELDEN RING' release may be delayed - GIGAZINE



in Game,   Security, Posted by log1p_kr