top | item 45028440

This House is Haunted: a decade-old RCE in the AION client

2 points| _zeta | 6 months ago |appsec.space

1 comment

order

_zeta|6 months ago

Exploring how AION’s old housing system, introduced over 10 years ago, left the client vulnerable to remote code execution through Lua scripting. Even though official servers removed the feature years ago, it’s still alive (and exploitable) in legacy versions. Write-up: https://appsec.space/posts/aion-housing-exploit/