TERA (Worldwide) – Chat Vulnerability

Message of a chat based vulnerability that could potentially lead to several severe server side exploits as well as remote execution of code on a players computer made the rounds overnight which affects all installations of TERA.

North American publisher En Masse Entertainment finally provided a statement regarding the vulnerability and are in contact with developer Bluehole.

Source: https://forums.enmasse.com/tera/discussion/18877/status-of-potential-chat-vulnerability

As of this post, Europe publisher Gameforge has yet to acknowledge the potential vulnerability (a forum posting includes more details of some of the potential effects which are pretty serious considering that many installations have the game running with administrator privs).

UPDATE: a Gameforge product community manager did re-open the thread so there is now some acknowledgement but not yet an official statement).

UPDATE #2: Both Gameforge and EME performed an emergency maintenance to disable most in-game chat temporarily while Bluehole investigates (or tries to figure out how to revamp their chat design and also tries to figure out which libraries contain vulnerabilities that need to be patched and hoping that other things do not break in the process).