Platform: Nintendo 3DS
One Piece: Unlimited Cruise SP2
Castlevania
The Legend of Zelda
The Mysterious Murasame Castle
Super Smash Bros. for Nintendo 3DS
Ace Combat: Assault Horizon Legacy
Wario's Woods
Zero Escape: Virtue's Last Reward
Metroid
Sayonara Umihara Kawase
Assassin's Creed: Lost Legacy
Kirby's Star Stacker
Yoshi
Power Rangers Megaforce
Pokémon Y
New Super Mario Bros. 2
Mega Man Xtreme
Qix
Spirit Camera: The Cursed Memoir
Donkey Kong
Shining Force: The Sword of Hajya
The Great Ace Attorney 2: Resolve
Yo-kai Watch 3
Regular Show: Mordecai and Rigby in 8-Bit Land
Mario Kart: Super Circuit
Pac-Man and the Ghostly Adventures 2
Donkey Kong Land 2
Mega Man Xtreme 2
Mega Man 4
Battle City
Mighty No. 9
Kid Icarus: Uprising
The Legend of Zelda: Oracle of Seasons
Fire Emblem: Shadow Dragon and the Blade of Light
Professor Layton and the Azran Legacy
One Piece: Unlimited World RED
Adventures of Lolo
Skylanders: Giants
HarmoKnight
Donkey Kong
Nintendogs + Cats: Golden Retriever & New Friends
Adventure Time: Explore the Dungeon Because I Don't Know!
SteamWorld Dig
Ghosts 'n Goblins
Miitopia
Joy Mech Fight
Mario Party: Star Rush
One Piece: Romance Dawn
Mega Man 6
Mario vs. Donkey Kong
Viewing Single Trivia
▲
4
▼
In 2021, dataminers discovered a consistent security vulnerability, later termed "ENLBufferPwn", in multiple Nintendo 3DS, Wii U, and Nintendo Switch games. ENLBufferPwn made it possible to inject code into another player's system during online multiplayer by deliberately triggering a buffer overflow in a game's "ENL" network library. The glitch was known to be possible in Animal Crossing: New Horizons, Arms, Mario Kart 7 (where the glitch instead targets the "Net" library), Mario Kart 8, Mario Kart 8 Deluxe, Nintendo Switch Sports, Splatoon, Splatoon 2, Splatoon 3, and Super Mario Maker 2, with other games potentially being affected.
ENLBufferPwn generated significant cybersecurity concerns due to its ease of execution, the fact that it could be pulled off without the target player's notice, and the wide range of actions that could occur through it, up to and including identity theft and espionage. Reflecting this, the United States federal government's National Vulnerability Database gave the glitch a 9.8 rating, reflecting critical threats to public safety. Following multiple reports issued by white hat hackers between 2021 and 2022, Nintendo patched all known affected games to remove the vulnerabilities that made ENLBufferPwn possible.
ENLBufferPwn generated significant cybersecurity concerns due to its ease of execution, the fact that it could be pulled off without the target player's notice, and the wide range of actions that could occur through it, up to and including identity theft and espionage. Reflecting this, the United States federal government's National Vulnerability Database gave the glitch a 9.8 rating, reflecting critical threats to public safety. Following multiple reports issued by white hat hackers between 2021 and 2022, Nintendo patched all known affected games to remove the vulnerabilities that made ENLBufferPwn possible.
GitHub page explaining ENLBufferPwn:
https://github.com/PabloMK7/ENLBufferPwn
National Vulnerability Database page on ENLBufferPwn:
https://nvd.nist.gov/vuln/detail/cve-2022-47949
Nintendo World Report article about the anti-ENLBufferPwn updates:
https://www.nintendoworldreport.com/news/62471/major-security-vulnerability-disclosed-in-multiple-nintendo-games
Bitdefender article about the anti-ENLBufferPwn updates:
https://www.bitdefender.com/en-us/blog/hotforsecurity/nintendo-patches-enlbufferpwn-vulnerability-that-could-lead-to-complete-console-takeover
https://github.com/PabloMK7/ENLBufferPwn
National Vulnerability Database page on ENLBufferPwn:
https://nvd.nist.gov/vuln/detail/cve-2022-47949
Nintendo World Report article about the anti-ENLBufferPwn updates:
https://www.nintendoworldreport.com/news/62471/major-security-vulnerability-disclosed-in-multiple-nintendo-games
Bitdefender article about the anti-ENLBufferPwn updates:
https://www.bitdefender.com/en-us/blog/hotforsecurity/nintendo-patches-enlbufferpwn-vulnerability-that-could-lead-to-complete-console-takeover
Comments (0)
You must be logged in to post comments.