Security Risk - UNITY-SEC-844

I have been looking at this thread after receiving an email:

We use Unity in a college environment so we would need to update the software on all machines if this poses any real security risk in our environment.

I have already emailed security@unity3d.com but I have not received any reply.

Is it needed? Does anyone know what security risk is involved here?

From the FAQ

This is a serious vulnerability, and if your computers are connected to the internet then you should upgrade immediately. Remote code execution means an attacker could run arbitrary code on a vulnerable editor, which means they can do basically anything they want.

Woah wait, just saw the 8 thought it said 9, man I was about to say…

Yes update, very important.

Thanks for the replies, if I just do a check for updates from within the software and make sure it is fully up to date, will this fix what is needed for this particular issue?

Thanks :slight_smile:

It will very likely say it is up to date, that button been broke forever. I would recommend this page sir Download Archive keep in mind however you might be wanting to update again very soon, 2017.2 will be coming with the wonderful full .net not hacked up unity version.

1 Like

It depends which version you have of Unity. For an important security patch, I would not rely on the automatic check. I would definitely manually check. Inside Unity, click Help->About Unity to see your current version. Security patches were made available for all of the recent branches. You need to apply the security patch for the version branch you are currently using. Which version are you currently using?

I agree with shiloh, however the finally getting over outdated stripped down terrible mono, I have been using the most recent beta branch and even with the bugs looooove it.