Marvel Contest has allegedly "major security vulnerabilities" to allow malicious code injection

According to a report published on a blog by cybersecurity researcher Shalzuth, one of the most popular multiplayer games on Steam, there is a "huge security hole."

据称《漫威争锋》存在“重大安全漏洞” 允许恶意代码注入

The vulnerability is said to allow hackers to access players’ PCs and PS5s.In the report, the developer used the "Remote Code Execution Hot Patch System", but when the code is executed, the "Game does not verify" command comes from the real server.In addition, since the game's anti-cheating requires administrator rights, the vulnerability is under administrator rights, which makes it easier for hackers to take over the device.

据称《漫威争锋》存在“重大安全漏洞” 允许恶意代码注入

This is a common method for hackers to run malicious code on player devices, but only if they use unsafe networks and victims do not notice them, such as public networks at airports and restaurants.Shalzuth injected malicious code under the same Wi-Fi through a video.He said that since the game does not have an official network security external communication channel, it has contacted the developer NetEase through various means and informed of the loopholes.But so far, he has not received any responses to the bug fix.

据称《漫威争锋》存在“重大安全漏洞” 允许恶意代码注入

Therefore, most players who play games at their own home do not need to worry too much, and the official will probably solve this problem as soon as possible.However, this is still a relatively important issue for a popular game.Currently, the number of players in Marvel Contest on Steam is around 200,000 to 300,000 per day.