Valve Patches Zero Day Vulnerabilities in Steam After Banning Researcher Who Discovered Them, Changes Bug Bounty Rules

Valve has called banning of the security researcher a mistake.

Advertisement
By Nadeem Sarwar | Updated: 23 August 2019 16:16 IST
Highlights
  • Valve initially refused to recognise the LPE as a serious issue
  • The LPE flaws could be exploited to gain admin privilege
  • The security researcher who found the LPEs remains banned

Russian security researcher, Vasily Kravets, was prohibited from going public with his discovery

Valve recently attracted a lot of criticism from the cyber-security community after turning away a researcher who discovered a couple of zero-day vulnerabilities in Steam, and eventually blocked him from its bug bounty platform. Valve has now taken cognisance of the whole incident, and after patching the two potentially serious Local Privilege Escalation (LPE) vulnerabilities, the company has called the treatment meted out to the researcher a mistake and has also updated its bug bounty programme rules. What is worth noting is that the Valve partner handling it initially refused to recognise the zero-day flaw as a serious issue, prompting the security researcher to disclose it publicly.

Russian security researcher, Vasily Kravets, discovered a Local Privilege Escalation (LPE) issue in Steam and proceeded to file a bug report. HackerOne, the Valve partner overseeing the Steam bug bounty programme, called the report out of scope and pointed that Valve has no intentions to patch it. Additionally, they forbade Kravets from disclosing the issues publicly, leaving millions of Steam users vulnerable to a flaw that could enable a local malware to exploit the Steam app for gaining admin rights and eventually taking over the host.

However, the security researcher eventually went public with his discovery leading to him being banned from the bug bounty programme by HackerOne. And even though Valve later rolled out a patch to fix it, an alternative way to exploit it was soon discovered. To make matters worse, Kravets eventually discovered a second LPE vulnerability and published it on his own, since he was unable to file the bug report.

Advertisement

The whole saga painted a negative picture of Valve as a company that is reckless with security and handles such vulnerabilities in an irresponsible fashion, in addition to treating researchers badly. But it appears that Valve has now rolled out a patch to fix the two LPE flaws in Steam, and more importantly, has admitted that ignoring Kravets' first report was a mistake. Valve also noted that whole saga was due to a misunderstanding of its bug bounty rules.

Advertisement

“Our HackerOne program rules were intended only to exclude reports of Steam being instructed to launch previously installed malware on a user's machine as that local user. Instead, misinterpretation of the rules also led to the exclusion of a more serious attack that also performed local privilege escalation through Steam," Valve was quoted as saying by ZDNet. Additionally, the company behind Steam has updated the rules of its bug bounty program to avoid such incidents in the future. While Valve's rule change is reassuring, the victim researcher is still banned from the Steam bug bounty program run by HackerOne.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Valve. Steam, HackerOne
Advertisement
Popular Mobile Brands
  1. Here's When the Realme 16 Pro Series Will Launch in India
  2. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  3. Here's How Much The Redmi Note 15 5G Could Cost in India
  4. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  5. Oppo Pad Air 5 Launch Date Announced: See Expected Features
  6. Sony's Year-End Holiday Sale on PS5 Accessories, Games Kicks Off Next Week
  7. Oppo Reno 15 Pro, Reno 15 Pro Max Global Variants Surface on Geekbench
  8. YouTube Bans Popular Channels for Making Misleading AI-Generated Movie Trailers
  9. Instagram Will Now Restrict the Number of Hashtags You Can Use
  1. New FIFA Game to Launch on Netflix Games in Time for FIFA World Cup Next Year
  2. Honor Magic V6 Tipped to Launch With 7,200mAh Dual-Cell Battery, Snapdragon 8 Elite Gen 5 SoC
  3. YouTube Bans Popular Indian Channel for Making Misleading AI-Generated Movie Trailers
  4. OpenAI Updates AI Guidelines to Prioritise Teen Safety Over Other Goals
  5. Dominic and The Ladies Purse Out on OTT: Know Everything About Streaming, Plot, Cast, and More
  6. Sony Announces Year-End Holiday Sale in India on PS5 Accessories, Games
  7. Xiaomi 17 Ultra Battery, Charging Specifications and Colourways Tipped Ahead of Launch
  8. Redmi Note 15 5G Price in India, Storage Configurations Tipped Ahead of January 6 Launch
  9. Little Hearts Streaming Now on Netflix: Know Everything About Plot, Cast, and More
  10. Crypto Traders Remain Cautious Amidst Tight Liquidity and Mixed Global Cues
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.