Platform: Nintendo 3DS
The Legend of Zelda: A Link Between Worlds
Pokémon Picross
Ghosts 'n Goblins
The Legend of Zelda: Oracle of Ages
Bravely Default: Flying Fairy
Theatrhythm Final Fantasy
Super Mario Land 2: 6 Golden Coins
Star Luster
New Super Mario Bros. 2
American Mensa Academy
The Mysterious Murasame Castle
Scribblenauts Unlimited
Adventures of Lolo
Ninja Gaiden
Mario Bros.
Naruto: Powerful Shippuden
Mighty Bomb Jack
Power Rangers Megaforce
Kirby's Block Ball
Kid Icarus: Uprising
Pokémon Alpha Sapphire
Epic Mickey: Power of Illusion
Rhythm Thief & the Emperor's Treasure
Tomodachi Life
Mario Kart: Super Circuit
Pokémon Blue Version
Pokémon Silver Version
Final Fantasy III
Yo-kai Watch 3
One Piece: Unlimited Cruise SP
Mario vs. Donkey Kong
Mario Kart 7
Fire Emblem Echoes: Shadows of Valentia
Sonic Generations
Mega Man
Code Name S.T.E.A.M.
Mario vs. Donkey Kong: Tipping Stars
HarmoKnight
Metroid II: Return of Samus
Shin Megami Tensei: Devil Summoner - Soul Hackers
The Legend of Zelda: Ocarina of Time 3D
Atlantis no Nazo
Mega Man II
Game & Watch Gallery 2
Lalaloopsy: Carnival of Friends
River City Ransom
Famicom Wars
Saints Row: Money Shot
Blaster Master
Balloon Kid
Viewing Single Trivia
▲
4
▼
In 2021, dataminers discovered a consistent security vulnerability, later termed "ENLBufferPwn", in multiple Nintendo 3DS, Wii U, and Nintendo Switch games. ENLBufferPwn made it possible to inject code into another player's system during online multiplayer by deliberately triggering a buffer overflow in a game's "ENL" network library. The glitch was known to be possible in Animal Crossing: New Horizons, Arms, Mario Kart 7 (where the glitch instead targets the "Net" library), Mario Kart 8, Mario Kart 8 Deluxe, Nintendo Switch Sports, Splatoon, Splatoon 2, Splatoon 3, and Super Mario Maker 2, with other games potentially being affected.
ENLBufferPwn generated significant cybersecurity concerns due to its ease of execution, the fact that it could be pulled off without the target player's notice, and the wide range of actions that could occur through it, up to and including identity theft and espionage. Reflecting this, the United States federal government's National Vulnerability Database gave the glitch a 9.8 rating, reflecting critical threats to public safety. Following multiple reports issued by white hat hackers between 2021 and 2022, Nintendo patched all known affected games to remove the vulnerabilities that made ENLBufferPwn possible.
ENLBufferPwn generated significant cybersecurity concerns due to its ease of execution, the fact that it could be pulled off without the target player's notice, and the wide range of actions that could occur through it, up to and including identity theft and espionage. Reflecting this, the United States federal government's National Vulnerability Database gave the glitch a 9.8 rating, reflecting critical threats to public safety. Following multiple reports issued by white hat hackers between 2021 and 2022, Nintendo patched all known affected games to remove the vulnerabilities that made ENLBufferPwn possible.
GitHub page explaining ENLBufferPwn:
https://github.com/PabloMK7/ENLBufferPwn
National Vulnerability Database page on ENLBufferPwn:
https://nvd.nist.gov/vuln/detail/cve-2022-47949
Nintendo World Report article about the anti-ENLBufferPwn updates:
https://www.nintendoworldreport.com/news/62471/major-security-vulnerability-disclosed-in-multiple-nintendo-games
Bitdefender article about the anti-ENLBufferPwn updates:
https://www.bitdefender.com/en-us/blog/hotforsecurity/nintendo-patches-enlbufferpwn-vulnerability-that-could-lead-to-complete-console-takeover
https://github.com/PabloMK7/ENLBufferPwn
National Vulnerability Database page on ENLBufferPwn:
https://nvd.nist.gov/vuln/detail/cve-2022-47949
Nintendo World Report article about the anti-ENLBufferPwn updates:
https://www.nintendoworldreport.com/news/62471/major-security-vulnerability-disclosed-in-multiple-nintendo-games
Bitdefender article about the anti-ENLBufferPwn updates:
https://www.bitdefender.com/en-us/blog/hotforsecurity/nintendo-patches-enlbufferpwn-vulnerability-that-could-lead-to-complete-console-takeover
Comments (0)
You must be logged in to post comments.