This House is Haunted: a decade-old RCE in the AION client

2 _zeta 1 8/26/2025, 4:05:57 PM appsec.space ↗

Comments (1)

_zeta · 2h ago
Exploring how AION’s old housing system, introduced over 10 years ago, left the client vulnerable to remote code execution through Lua scripting. Even though official servers removed the feature years ago, it’s still alive (and exploitable) in legacy versions. Write-up: https://appsec.space/posts/aion-housing-exploit/