ENLBufferPwn: Severe vulnerability in first party 3DS, Wii U and Switch games

enlbufferpwn_logo.png

ENLBufferPwn (CVE-2022-47949) is a vulnerability in the network code used in many first party Nintendo games since the 3DS. Combined with the right techniques, it allows remote code execution in the victim's console by just having an online game session with the attacker. The vulnerability was discovered by multiple people independently during 2021 and reported to Nintendo during 2021/2022. The severity of the vulnerability has been calculated as 9.8/10 (Critical) by the CVSS 3.1 calculator.

Combined with other OS vulnerabilities, full remote console takeover can be achieved. This has been demonstrated in the case of Mario Kart 7, where a payload is sent to launch SafeB9SInstaller. However, it is theoretically possible to do other malicious activities, such as stealing account/credit card information or taking unauthorized audio/video recordings using the console built-in mic/cameras.

Here is a list of games that are known to have had the vulnerability at some point (all the Switch and 3DS games listed have received updates that patch the vulnerability, so they are no longer affected):
  • Mario Kart 7 (fixed in v1.2)
  • Mario Kart 8 (still not fixed)
  • Mario Kart 8 Deluxe (fixed in v2.1.0)
  • Animal Crossing: New Horizons (fixed in v2.0.6)
  • ARMS (fixed in v5.4.1)
  • Splatoon (still not fixed)
  • Splatoon 2 (fixed in v5.5.1)
  • Splatoon 3 (fixed in late 2022, exact version unknown)
  • Super Mario Maker 2 (fixed in v3.0.2)
  • Nintendo Switch Sports (fixed in late 2022, exact version unknown)
  • Probably more...
Below you can find proof of concept videos showcasing the vulnerability in Mario Kart 7 and Mario Kart 8.





A full report of the vulnerability can be found in the following GitHub repository.
:arrow: Full vulnerability report (GitHub)
 
Last edited by PabloMK7,

pustal

Yeah! This is happenin'!
Member
Joined
Jul 19, 2011
Messages
1,562
Trophies
2
Location
Emerald Coast
Website
web.archive.org
XP
6,288
Country
Portugal
Don’t store payment details on your console, use 2FA - always been my policy. Recommend that others do the same.

Use digital one use cards. Even if you delete them, with some companies history I wouldn't be surprised the infor prevailed somehow in their servers.
 

hippy dave

BBMB
Member
Joined
Apr 30, 2012
Messages
9,917
Trophies
2
XP
29,910
Country
United Kingdom
I wonder how far up the line it can go on the Switch.
It's an entry point, so you won't get a full hack without chaining it to a kernel exploit etc. Unfortunately those are believed not to exist on current firmware, but if someone has a console on old firmware that's already susceptible to pegascape, they could probably exploit it through Mario Kart instead for the lols.
 
Joined
Mar 30, 2011
Messages
1,292
Trophies
2
Age
32
Location
Arcadia
XP
3,760
Country
Italy
Lmao, not only is their online services complete ass, now this too! Has this crap like ever happened on them Sony consoles or Microsoft? Genuinely asking because I'm not sure, heh.
At least it seems they've been stepping up their game to fix this shit, but damn, just... Craptendo and anything regarding the internet are basically opposites of each other, heh.
 

PopcornSweetie

Well-Known Member
Member
Joined
Aug 24, 2022
Messages
297
Trophies
0
Location
New York
XP
1,085
Country
United States
Lmao, not only is their online services complete ass, now this too! Has this crap like ever happened on them Sony consoles or Microsoft? Genuinely asking because I'm not sure, heh.
At least it seems they've been stepping up their game to fix this shit, but damn, just... Craptendo and anything regarding the internet are basically opposites of each other, heh.
All i know is that both Sony and Microsoft got their servers hacked a couple or times (especially in the PS3/X360 era)
 

SG854

Hail Mary
Member
Joined
Feb 17, 2017
Messages
5,215
Trophies
1
Location
N/A
XP
8,104
Country
Congo, Republic of the
Lmao, not only is their online services complete ass, now this too! Has this crap like ever happened on them Sony consoles or Microsoft? Genuinely asking because I'm not sure, heh.
At least it seems they've been stepping up their game to fix this shit, but damn, just... Craptendo and anything regarding the internet are basically opposites of each other, heh.
There was the Sony 2011 hack. Their PSN internet was down for almost a whole month, 23 days. I remember that.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • ShinyLuxio @ ShinyLuxio:
    @BigOnYa thanks but my question isn't there
  • BigOnYa @ BigOnYa:
    You ask your questions there, create a new thread if its not already answered, then eventually a 3ds genius will respond.
  • ShinyLuxio @ ShinyLuxio:
    I will, thanks
    +1
  • BigOnYa @ BigOnYa:
    No prob and btw, welcome to gbatemp! :grog:
  • BigOnYa @ BigOnYa:
    @K3Nv2 I got some cheapies at wallys, that are pretty good, already have lost a few expensive ones (one falls out and gone, can't find) while cutting grass so bought some cheap ones, and of course never lose these cheap ones. (Cheap meaning only $35, compared to air buds which I only have 1 of 2 now)
  • BigOnYa @ BigOnYa:
    They need to add air tags to they airbuds..
  • The Real Jdbye @ The Real Jdbye:
    @BigOnYa the airtags are bigger than the airpods, they won't fit
    +1
  • BigOnYa @ BigOnYa:
    Be cool tech tho. Of course they want to lose them anyways. Buy and buy again.
  • K3Nv2 @ K3Nv2:
    Apple could make a find my AirPods thing pretty easily
    +1
  • BigOnYa @ BigOnYa:
    You would think, esp using bluetooth, not GPS, like a "your getting hot-er" meter on your phone.
  • BigOnYa @ BigOnYa:
    I think they should tie up diddy, and let all the victims come and abuse him, we'll make a holiday of it every year. (jk, maybe)
  • BigOnYa @ BigOnYa:
    I'm starting to sound like a Tck Gonna cut myself off.
  • K3Nv2 @ K3Nv2:
    It's not 4th of July yet
  • Veho @ Veho:
    It is in India.
  • Veho @ Veho:
    Wow, only $700?
  • SnowStormAkikaze @ SnowStormAkikaze:
    Hey :)
    If I book mark the topic where can I read them?
  • Veho @ Veho:
    Click on your profile pic in the top right corner, and you'll get the profile menu popup, with the profile icon highlighted at the top, and the "bookmarks" banner next to it in gray. Click on that icon and you'll get a list of your bookmarks.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Banners we don't need no stinking banners! Lol
    +1
  • AncientBoi @ AncientBoi:
    [bans you for not taking a bath] :tpi::rofl2::tpi:
  • Veho @ Veho:
    Who bans the banners?
    +1
  • AncientBoi @ AncientBoi:
    I just did
    AncientBoi @ AncientBoi: I just did