A security YouTuber, Shalzuth, has uncovered that the popular multiplayer shooter, Marvel Rivals, might be leaving its players incredibly exposed. However, due to the YouTube channel’s small size, this has gone unnoticed since he posted the breakdown on January 31.
The security exploit allows hackers to potentially take over your entire PC. While the video didn’t go into technical details, Shalzuth shows it hitting a PC and also allowing an entry point to the PS5 version of the game.
Marvel Rivals is incredibly popular, with a regular 200, 000 people online concurrently playing it. It currently contains a method of deploying a remote code execution through the game’s patching system. This is originally intended to allow developers to update parts of the game without having to bring it entirely offline.
The hotfix solution is open to anyone on the same network, and to make matters worse, Marvel Rivals runs with administrator privileges on Windows. With these activated, if the right person got their hands on this exploit, it could do some serious damage.
Marvel Rivals leaves its players open to attack
As Shalzuth states on his blog, this would allow anyone to potentially fake a hotfix for the game, and access your computer. All they’d have to do is connect to the same network.
In the video demo, Shalzuth shows a custom script that will sniff for packets on the network. Once it detects activity for Marvel Rivals connecting to the server, the malicious user can then deploy scripts. The demo deploys a Python script, which could easily be used to mine cryptocurrency or secure passwords and sensitive information.
Thankfully the scope of the issue will rely on that attacker being on the same network. But, if someone were to say, connect to the game over their college or university network, this could be a point of attack.
Shalzuth finishes off by explaining the gaps. A major flaw in Marvel Rivals, aside from running at administrator levels for its anti-cheat, is that the game apparently doesn’t check to see if it is connected to a real server. With this massive gap in the way, Marvel Rivals players are actively at risk.
He claims that he contacted NetEase, the developer, but hadn’t received any timeline for a fix as of the publish date. ReadWrite has reached out to NetEase for comment.
Featured image: Wikicommons, NetEase