{"id":130868,"date":"2022-12-28T11:15:00","date_gmt":"2022-12-28T11:15:00","guid":{"rendered":"https:\/\/www.nintendolife.com\/#article-143045"},"modified":"2022-12-28T11:15:00","modified_gmt":"2022-12-28T11:15:00","slug":"nintendo-has-been-patching-a-severe-vulnerability-found-in-some-online-switch-3ds-and-wii-u-games","status":"publish","type":"post","link":"https:\/\/sickgaming.net\/blog\/2022\/12\/28\/nintendo-has-been-patching-a-severe-vulnerability-found-in-some-online-switch-3ds-and-wii-u-games\/","title":{"rendered":"Nintendo Has Been Patching A &#8220;Severe&#8221; Vulnerability Found In Some Online Switch, 3DS, And Wii U Games"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/images.nintendolife.com\/67df572291b91\/large.jpg\"><img decoding=\"async\" src=\"https:\/\/images.nintendolife.com\/67df572291b91\/small.jpg\" class=\"media_thumbnail\"><\/a><\/div>\n<figure class=\"picture\"><a class=\"scanlines\" title=\"Switch\" href=\"https:\/\/images.nintendolife.com\/67df572291b91\/switch.large.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"lazy\" src=\"image\/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCA5MDAgNTA3Ij48L3N2Zz4=\" width=\"900\" height=\"507\" data-original=\"https:\/\/images.nintendolife.com\/67df572291b91\/switch.900x.jpg\" alt=\"Switch\"><\/a><figcaption class=\"caption\"><em class=\"credit\">Image: Damien McFerran \/ Nintendo Life<\/em><\/figcaption><\/figure>\n<p>A severe vulnerability affecting several Nintendo consoles was found recently, with the potential to allow unauthorised access to Switch, 3DS, and Wii U via a host of online games. It&#8217;s reported that for some time Nintendo has been working to patch games to eliminate the exploit known as &#8216;ENLBufferPwn&#8217;, with several updates already live to address the situation (thanks, <a href=\"https:\/\/nintendoeverything.com\/enlbufferpwn-exploit-switch-3ds-wii-u-games\/\">Nintendo Everything<\/a>).<\/p>\n<p>The vulnerability, which has been categorised as <a href=\"https:\/\/www.first.org\/cvss\/calculator\/3.1#CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H\">&#8216;Critical&#8217; on the Common Vulnerability Scoring System (CVSS)<\/a> and detailed in full on <a href=\"https:\/\/github.com\/PabloMK7\/ENLBufferPwn\">GitHub<\/a> by <a href=\"https:\/\/twitter.com\/Pablomf6\/status\/1606637941329215488\">PabloMK7<\/a>, <a href=\"https:\/\/github.com\/Rambo6Glaz\">Rambo6Glaz<\/a>, and <a href=\"https:\/\/twitter.com\/fishguy6564\">Fishguy6564<\/a>, reportedly exposes a victim&#8217;s device to complete remote control by simply playing an online game with a potential attacker. This means that attackers may gain access to sensitive information or take audio and video recordings by remotely executing code.<\/p>\n<p>The vulnerability was reported to Nintendo in &#8220;2021\/2022&#8221; by <a href=\"https:\/\/twitter.com\/Pablomf6\/status\/1606637949382180864\">@Pablomf6<\/a> \u2014 who says they received a $1000 &#8220;bounty&#8221; via Nintendo&#8217;s <a href=\"https:\/\/hackerone.com\/nintendo\">HackerOne<\/a> program \u2014 and it is now understood that the company has taken action to fix the issue in some of the affected games, including <a href=\"https:\/\/www.nintendolife.com\/games\/3ds\/mario_kart_7\">Mario Kart 7<\/a>, which was <a href=\"https:\/\/www.nintendolife.com\/news\/2022\/12\/mario-kart-7-gets-its-first-update-in-over-a-decade\">recently updated after more than a decade<\/a>.<\/p>\n<p>It seems most high-profile Switch titles have already been fixed, but it looks like <a href=\"https:\/\/www.nintendolife.com\/games\/wiiu\/mario_kart_8\">Mario Kart 8<\/a> and <a href=\"https:\/\/www.nintendolife.com\/games\/wiiu\/splatoon\">Splatoon<\/a> on Wii U have yet to be addressed and may still be affected by the vulnerability.<\/p>\n<p>Here&#8217;s a list of affected titles, as per the <a href=\"https:\/\/github.com\/PabloMK7\/ENLBufferPwn\">GitHub page<\/a>:<\/p>\n<p>It&#8217;s speculated that other games may also be affected by the vulnerability, although that&#8217;s unconfirmed at present.<\/p>\n<p>For a look at the exploit in action, take a peek at the below video from PabloMK7 which demonstrates an attacker (left console) remotely taking over an unmodified 3DS (right side) by copying a return-oriented programming (ROP) payload and executing it remotely. The victim console is then forced to run a custom firmware installer and it&#8217;s thought that the same technique would allow an attacker to steal sensitive information from a remote console. Thankfully, this has now been fixed and can no longer be carried out if you&#8217;re running the latest version of the software, so be sure to update if you haven&#8217;t!<\/p>\n<aside class=\"object object-youtube\">\n<figure class=\"youtube\" data-videoid=\"PLAVmp5ky-k\">[embedded content]<figcaption class=\"youtube-sub\">Subscribe to <a class=\"external\" rel=\"noopener\" href=\"https:\/\/www.youtube.com\/subscription_center?add_user=nintendolife\">Nintendo Life<\/a> on <span class=\"g-ytsubscribe\" data-channel=\"nintendolife\" data-layout=\"default\" data-count=\"default\"><a class=\"external\" rel=\"noopener\" href=\"https:\/\/www.youtube.com\/nintendolife\">YouTube<\/a><\/span><\/figcaption><\/figure>\n<\/aside>\n<p>Nintendo&#8217;s relatively limited approach to online play seems to have its advantages when it comes to security issues like this, as pointed out by <a href=\"https:\/\/twitter.com\/LuigiBlood\">@LuigiBlood<\/a> discussing the exploit:<\/p>\n<aside class=\"object object-tweet\"><!-- cache: oembed\/https:\/\/twitter.com\/luigiblood\/statuses\/1606764091162361856 @ 2022-12-29T09:23:10+00:00 --><\/p>\n<blockquote class=\"twitter-tweet\"><p><span lang=\"en\" dir=\"ltr\">Unless Nintendo gave their network library (Not NEX!) to some external devs like Camelot, Arika and Bandai Namco which I very highly doubt, I think Wii U and 3DS online will still be around for a while.<br \/>At worst they could just cut online for these games only.<\/span>\u2014 Yakumono (@LuigiBlood) <a href=\"https:\/\/twitter.com\/LuigiBlood\/status\/1606764091162361856?ref_src=twsrc%5Etfw\">December 24, 2022<\/a><\/p><\/blockquote>\n<\/aside>\n<p>Those two games mentioned are Mario Kart 8 and Splatoon, so if you still play either of those titles online on your Wii U, we recommend exercising extreme caution or avoiding them altogether until more information is available. We&#8217;ll update this article if further details come to light.<\/p>\n<p><em>What do you make of this? Share your thoughts in the comments below.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Image: Damien McFerran \/ Nintendo Life A severe vulnerability affecting several Nintendo consoles was found recently, with the potential to allow unauthorised access to Switch, 3DS, and Wii U via a host of online games. It&#8217;s reported that for some time Nintendo has been working to patch games to eliminate the exploit known as &#8216;ENLBufferPwn&#8217;, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[],"class_list":["post-130868","post","type-post","status-publish","format-standard","hentry","category-nintendo-news"],"_links":{"self":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/130868","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/comments?post=130868"}],"version-history":[{"count":0,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/posts\/130868\/revisions"}],"wp:attachment":[{"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/media?parent=130868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/categories?post=130868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sickgaming.net\/blog\/wp-json\/wp\/v2\/tags?post=130868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}