Valve Patches Zero Day Vulnerabilities in Steam After Banning Researcher Who Discovered Them, Changes Bug Bounty Rules

Valve has called banning of the security researcher a mistake.

Advertisement
By Nadeem Sarwar | Updated: 23 August 2019 16:16 IST
Highlights
  • Valve initially refused to recognise the LPE as a serious issue
  • The LPE flaws could be exploited to gain admin privilege
  • The security researcher who found the LPEs remains banned

Russian security researcher, Vasily Kravets, was prohibited from going public with his discovery

Valve recently attracted a lot of criticism from the cyber-security community after turning away a researcher who discovered a couple of zero-day vulnerabilities in Steam, and eventually blocked him from its bug bounty platform. Valve has now taken cognisance of the whole incident, and after patching the two potentially serious Local Privilege Escalation (LPE) vulnerabilities, the company has called the treatment meted out to the researcher a mistake and has also updated its bug bounty programme rules. What is worth noting is that the Valve partner handling it initially refused to recognise the zero-day flaw as a serious issue, prompting the security researcher to disclose it publicly.

Russian security researcher, Vasily Kravets, discovered a Local Privilege Escalation (LPE) issue in Steam and proceeded to file a bug report. HackerOne, the Valve partner overseeing the Steam bug bounty programme, called the report out of scope and pointed that Valve has no intentions to patch it. Additionally, they forbade Kravets from disclosing the issues publicly, leaving millions of Steam users vulnerable to a flaw that could enable a local malware to exploit the Steam app for gaining admin rights and eventually taking over the host.

However, the security researcher eventually went public with his discovery leading to him being banned from the bug bounty programme by HackerOne. And even though Valve later rolled out a patch to fix it, an alternative way to exploit it was soon discovered. To make matters worse, Kravets eventually discovered a second LPE vulnerability and published it on his own, since he was unable to file the bug report.

Advertisement

The whole saga painted a negative picture of Valve as a company that is reckless with security and handles such vulnerabilities in an irresponsible fashion, in addition to treating researchers badly. But it appears that Valve has now rolled out a patch to fix the two LPE flaws in Steam, and more importantly, has admitted that ignoring Kravets' first report was a mistake. Valve also noted that whole saga was due to a misunderstanding of its bug bounty rules.

“Our HackerOne program rules were intended only to exclude reports of Steam being instructed to launch previously installed malware on a user's machine as that local user. Instead, misinterpretation of the rules also led to the exclusion of a more serious attack that also performed local privilege escalation through Steam," Valve was quoted as saying by ZDNet. Additionally, the company behind Steam has updated the rules of its bug bounty program to avoid such incidents in the future. While Valve's rule change is reassuring, the victim researcher is still banned from the Steam bug bounty program run by HackerOne.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Valve. Steam, HackerOne
Advertisement
Popular Mobile Brands
  1. OTT Releases of the Week (Oct 13th - Oct 19th): What to Stream This Weekend?
  2. Vivo Confirms OriginOS 6 Update Schedule in India: See Release Timeline
  3. Kantara: A Legend Chapter-1 Lands on Amazon Prime Video Soon
  4. Satellites Capture Record-Breaking 20-Metre Waves Crossing Entire Oceans
  5. Tiger Shroff's Baaghi 4 to Land on OTT Platforms Soon: All the Details
  6. OnePlus Pad 2 With Dimensity 9400+ SoC to Launch Alongside OnePlus 15
  7. Bhagwat Chapter 1: Raakshas OTT Release Details Revealed
  8. OnePlus 15 Confirmed to Debut in These Three Colourways
  9. Lava Probuds Aria 911 Mega Flash Sale: Get Lava's TWS Earbuds for Rs 21
  10. Borderlands 4 Review: Guns Gone Wild
  1. Shakthi Thirumagan OTT Release: When, Where to Watch Vijay Antony-Starrer Action Thriller Online?
  2. Former Assassin's Creed Boss Says He Was Asked to 'Step Aside' by Ubisoft
  3. Arshad Warsi's Bhagwat Chapter 1: Raakshas OTT Release: Everything You Need to Know About This Thriller
  4. Vivo Confirms OriginOS 6 Update Rollout Schedule in India: Check Full Release Timeline
  5. Huawei Nova Flip S Launched With 4,400mAh Battery, 2.14-Inch Cover Screen: Price, Features
  6. The Fantastic Four: First Steps Reportedly Set for OTT Debut Soon: All You Need to Know
  7. Huawei Nova 14 Vitality Edition Launched With 5,500mAh Battery, 50-Megapixel Selfie Camera: Price, Specifications
  8. Anthropic Connects Claude With Microsoft 365 Platforms, Can Pull Information From Outlook and Teams
  9. Red Magic 11 Pro Series Launched With Snapdragon Elite Gen 5, Liquid Cooling: Price, Specifications
  10. Nintendo Aims to Make 25 Million Switch 2 Units by March 2026 to Set Gaming History
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.