VendorsUbisoftuplayall versions
Vulnerabilities

Ubisoft Uplay

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-15832
upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process.
Published 2018-09-20 · Modified
8.8EPSS 0.037
CVE-2019-14737
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
Published 2019-10-14 · Modified
7.81 PoCEPSS 0.017