CVE-2012-4177: Ubi Uplay Pc

High severity, CVSS 10.0. EPSS: 58% chance of exploitation in the next 30 days.

The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.

Affected products

  • Ubi Uplay Pc: up to and including 2.0.3; version 2.0 only; version 2.0.1 only; version 2.0.2 only

Published 2012-08-07. Last modified 2026-06-16.