Platform: Nintendo 3DS
HarmoKnight
Mario Tennis Open
Pokémon Ultra Moon
Super C
Spirit Camera: The Cursed Memoir
Bio Miracle Bokutte Upa
Mega Man
Fire Emblem Fates: Special Edition
The Binding of Isaac: Rebirth
Nekketsu Kouha Kunio-kun: Bangai Rantou-hen
Punch-Out!!
Ghosts 'n Goblins
Pilotwings Resort
Sonic Labyrinth
Fire Emblem Awakening
Senran Kagura 2: Deep Crimson
Dr. Mario
Kirby's Dream Land 2
Monster Hunter 3 Ultimate
One Piece: Dai Kaizoku Colosseum
Mario & Luigi: Bowser's Inside Story + Bowser Jr.'s Journey
Gravity Falls: Legend of the Gnome Gemulets
Game & Watch Gallery
Pokémon Alpha Sapphire
Mario Bros.
Terraria
Mega Man X
Citizens of Earth
Cave Story 3D
Mario Sports Superstars
Pokémon Omega Ruby
Pokémon Art Academy
Cave Story
Dead or Alive: Dimensions
F-Zero: Maximum Velocity
LovePlus
Project X Zone
Metroid Fusion
Dragon Ball Fusions
Fire Emblem Echoes: Shadows of Valentia
Rune Factory 4
Conception II: Children of the Seven Stars
Yo-kai Watch 3
Sonic Lost World
Wario Land 4
Mega Man 7
Yoshi
Yo-Kai Watch 2: Bony Spirits
Puzzle & Dragons Z + Puzzle & Dragons: Super Mario Bros. Edition
Mighty Bomb Jack
Viewing Single Trivia
▲
4
▼
In 2021, dataminers discovered a consistent security vulnerability, later termed "ENLBufferPwn", in multiple Nintendo 3DS, Wii U, and Nintendo Switch games. ENLBufferPwn made it possible to inject code into another player's system during online multiplayer by deliberately triggering a buffer overflow in a game's "ENL" network library. The glitch was known to be possible in Animal Crossing: New Horizons, Arms, Mario Kart 7 (where the glitch instead targets the "Net" library), Mario Kart 8, Mario Kart 8 Deluxe, Nintendo Switch Sports, Splatoon, Splatoon 2, Splatoon 3, and Super Mario Maker 2, with other games potentially being affected.
ENLBufferPwn generated significant cybersecurity concerns due to its ease of execution, the fact that it could be pulled off without the target player's notice, and the wide range of actions that could occur through it, up to and including identity theft and espionage. Reflecting this, the United States federal government's National Vulnerability Database gave the glitch a 9.8 rating, reflecting critical threats to public safety. Following multiple reports issued by white hat hackers between 2021 and 2022, Nintendo patched all known affected games to remove the vulnerabilities that made ENLBufferPwn possible.
ENLBufferPwn generated significant cybersecurity concerns due to its ease of execution, the fact that it could be pulled off without the target player's notice, and the wide range of actions that could occur through it, up to and including identity theft and espionage. Reflecting this, the United States federal government's National Vulnerability Database gave the glitch a 9.8 rating, reflecting critical threats to public safety. Following multiple reports issued by white hat hackers between 2021 and 2022, Nintendo patched all known affected games to remove the vulnerabilities that made ENLBufferPwn possible.
GitHub page explaining ENLBufferPwn:
https://github.com/PabloMK7/ENLBufferPwn
National Vulnerability Database page on ENLBufferPwn:
https://nvd.nist.gov/vuln/detail/cve-2022-47949
Nintendo World Report article about the anti-ENLBufferPwn updates:
https://www.nintendoworldreport.com/news/62471/major-security-vulnerability-disclosed-in-multiple-nintendo-games
Bitdefender article about the anti-ENLBufferPwn updates:
https://www.bitdefender.com/en-us/blog/hotforsecurity/nintendo-patches-enlbufferpwn-vulnerability-that-could-lead-to-complete-console-takeover
https://github.com/PabloMK7/ENLBufferPwn
National Vulnerability Database page on ENLBufferPwn:
https://nvd.nist.gov/vuln/detail/cve-2022-47949
Nintendo World Report article about the anti-ENLBufferPwn updates:
https://www.nintendoworldreport.com/news/62471/major-security-vulnerability-disclosed-in-multiple-nintendo-games
Bitdefender article about the anti-ENLBufferPwn updates:
https://www.bitdefender.com/en-us/blog/hotforsecurity/nintendo-patches-enlbufferpwn-vulnerability-that-could-lead-to-complete-console-takeover
Comments (0)
You must be logged in to post comments.