Detects two serious vulnerabilities on uTorrent that can help hackers execute malicious code or view download history on your computer
Hackers can take advantage of these two vulnerabilities to view the history of downloading or executing malware on a user's computer.
Google Zero project researchers have discovered two serious Remote Code Execution vulnerabilities in the popular versions of uTorrent web and desktop versions of BitTorrent. Hackers can take advantage of these two vulnerabilities to view the history of downloading or executing malware on a user's computer.
Security researcher Tavis Ormandy had to wait 90 since he notified uTorrent to announce his findings to users.
Tavis Ormandy's announcement on Twitter.
According to Ormandy, uTorrent's desktop version and web version vulnerabilities are related to various JSON-RPC issues. Both use a web interface to display web content.
By hiding commands (downloading malware to your computer's startup folder or accessing user download information) within web pages and interacting with uTorrent's RPC servers, An attacker with a fake website can exploit the client side vulnerability.
BitTorrent said the vulnerability was fixed in the most recent beta version of the desktop uTorrent Windows app. A patch for existing customers will be released in the next few days.
To fix this vulnerability, users can download a vulnerable version of the desktop version 3.5.3.44352 (http://www.utorrent.com/downloads/complete/track/beta/os/win) .
See more:
- The source code for iOS is revealed on GitHub as 'real goods', this is the time to reveal the biggest information in history
- How to protect high-risk network ports?
- Microsoft released an emergency patch for Windows, turned off the Specter patch, causing a drop in system performance
- Critical vulnerabilities discovered in Framework Electron, Skype, Slack, Twitch and a series of affected apps
You've just finished reading the article "Detects two serious vulnerabilities on uTorrent that can help hackers execute malicious code or view download history on your computer" edited by the TipsMake team. You can save this article to your computer here to read later or print it out. We hope this article has provided you with many useful tech tips and tricks. You can search for similar articles on tips and guides. Thank you for reading and for following us regularly.
- Detects code execution vulnerabilities in WinRAR, noting more than 100 infringement cases
- Warning: The new Facebook virus, a malicious code that is spreading rapidly through Messenger
- Warning of new malware appear like Wannacry, capable of deleting Vietnamese percussion on computer
- After WannaCry, Petya's 'extortion' malicious code is raging, this is a remedy to prevent
- How to automatically turn off the computer when downloading files on uTorrent
- 3 ways to view download history on Chrome