Valve Patches Zero Day Vulnerabilities in Steam After Banning Researcher Who Discovered Them, Changes Bug Bounty Rules

Valve has called banning of the security researcher a mistake.

Advertisement
By Nadeem Sarwar | Updated: 23 August 2019 16:16 IST
Highlights
  • Valve initially refused to recognise the LPE as a serious issue
  • The LPE flaws could be exploited to gain admin privilege
  • The security researcher who found the LPEs remains banned

Russian security researcher, Vasily Kravets, was prohibited from going public with his discovery

Valve recently attracted a lot of criticism from the cyber-security community after turning away a researcher who discovered a couple of zero-day vulnerabilities in Steam, and eventually blocked him from its bug bounty platform. Valve has now taken cognisance of the whole incident, and after patching the two potentially serious Local Privilege Escalation (LPE) vulnerabilities, the company has called the treatment meted out to the researcher a mistake and has also updated its bug bounty programme rules. What is worth noting is that the Valve partner handling it initially refused to recognise the zero-day flaw as a serious issue, prompting the security researcher to disclose it publicly.

Russian security researcher, Vasily Kravets, discovered a Local Privilege Escalation (LPE) issue in Steam and proceeded to file a bug report. HackerOne, the Valve partner overseeing the Steam bug bounty programme, called the report out of scope and pointed that Valve has no intentions to patch it. Additionally, they forbade Kravets from disclosing the issues publicly, leaving millions of Steam users vulnerable to a flaw that could enable a local malware to exploit the Steam app for gaining admin rights and eventually taking over the host.

Advertisement

However, the security researcher eventually went public with his discovery leading to him being banned from the bug bounty programme by HackerOne. And even though Valve later rolled out a patch to fix it, an alternative way to exploit it was soon discovered. To make matters worse, Kravets eventually discovered a second LPE vulnerability and published it on his own, since he was unable to file the bug report.

The whole saga painted a negative picture of Valve as a company that is reckless with security and handles such vulnerabilities in an irresponsible fashion, in addition to treating researchers badly. But it appears that Valve has now rolled out a patch to fix the two LPE flaws in Steam, and more importantly, has admitted that ignoring Kravets' first report was a mistake. Valve also noted that whole saga was due to a misunderstanding of its bug bounty rules.

Advertisement

“Our HackerOne program rules were intended only to exclude reports of Steam being instructed to launch previously installed malware on a user's machine as that local user. Instead, misinterpretation of the rules also led to the exclusion of a more serious attack that also performed local privilege escalation through Steam," Valve was quoted as saying by ZDNet. Additionally, the company behind Steam has updated the rules of its bug bounty program to avoid such incidents in the future. While Valve's rule change is reassuring, the victim researcher is still banned from the Steam bug bounty program run by HackerOne.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Valve. Steam, HackerOne
Advertisement
Popular Mobile Brands
  1. Here's When the Samsung Galaxy M47 5G Will Launch in India
  2. Here's How Much the Upcoming Vivo X Fold 6 Might Cost
  3. Everything New in Apple's iOS 27 Developer Beta 2 Update for iPhone
  4. Nothing Phone 4b Will Launch in India on This Date
  5. Redmi 17C Debuts With MediaTek Helio G81 Ultra Chip, 5,160mAh Battery
  6. Taiko Urges Users to Withdraw Funds After $1.7 Million Bridge Exploit
  7. The Oppo Reno 16 and Reno 16c Could Launch in India on This Date
  8. Realme P4x Debuts With 8,000mAh Battery and 4G Connectivity
  9. Samsonite's Latest Tracking Feature Is Designed to Help You Find Your Luggage
  10. RedMagic Gaming Tablet 5 Pro Set to Launch on This Date
  1. Taiko Urges Users to Move Funds Following $1.7 Million Bridge Exploit
  2. Samsonite Zipprix FT Suitcase Unveiled With Built-In Waypoint Luggage Tracking System: Price, Features
  3. Redmi 17C Launched With 5,160mAh Battery, MediaTek Helio G81 Ultra Chip: Price, Features
  4. Hideo Kojima's Horror Title OD Will Feature 'New Game System' That Pushes Users to Keep Playing
  5. Vivo X Fold 6 Price, Storage Variants and Key Specifications Leaked Ahead of June 26 Launch in China
  6. Realme P4x Launched With 8,000mAh Battery, 6.8-Inch Display and 4G Connectivity: Price, Specifications
  7. WhatsApp Desktop, WhatsApp Web Users Targeted Using Malware Campaign, Kaspersky Warns
  8. Bitcoin Nears Key Resistance Level as US-Iran Talks Lift Market Sentiment
  9. Apple Rolls Out iOS 27 Developer Beta 2 Update for iPhone With RCS Upgrades, New Siri Tools
  10. Samsung Galaxy M47 5G India Launch Date Announced; Key Specifications, Colour Options Revealed
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.