Valve Patches Zero Day Vulnerabilities in Steam After Banning Researcher Who Discovered Them, Changes Bug Bounty Rules

Valve has called banning of the security researcher a mistake.

Advertisement
By Nadeem Sarwar | Updated: 23 August 2019 16:16 IST
Highlights
  • Valve initially refused to recognise the LPE as a serious issue
  • The LPE flaws could be exploited to gain admin privilege
  • The security researcher who found the LPEs remains banned

Russian security researcher, Vasily Kravets, was prohibited from going public with his discovery

Valve recently attracted a lot of criticism from the cyber-security community after turning away a researcher who discovered a couple of zero-day vulnerabilities in Steam, and eventually blocked him from its bug bounty platform. Valve has now taken cognisance of the whole incident, and after patching the two potentially serious Local Privilege Escalation (LPE) vulnerabilities, the company has called the treatment meted out to the researcher a mistake and has also updated its bug bounty programme rules. What is worth noting is that the Valve partner handling it initially refused to recognise the zero-day flaw as a serious issue, prompting the security researcher to disclose it publicly.

Russian security researcher, Vasily Kravets, discovered a Local Privilege Escalation (LPE) issue in Steam and proceeded to file a bug report. HackerOne, the Valve partner overseeing the Steam bug bounty programme, called the report out of scope and pointed that Valve has no intentions to patch it. Additionally, they forbade Kravets from disclosing the issues publicly, leaving millions of Steam users vulnerable to a flaw that could enable a local malware to exploit the Steam app for gaining admin rights and eventually taking over the host.

Advertisement

However, the security researcher eventually went public with his discovery leading to him being banned from the bug bounty programme by HackerOne. And even though Valve later rolled out a patch to fix it, an alternative way to exploit it was soon discovered. To make matters worse, Kravets eventually discovered a second LPE vulnerability and published it on his own, since he was unable to file the bug report.

The whole saga painted a negative picture of Valve as a company that is reckless with security and handles such vulnerabilities in an irresponsible fashion, in addition to treating researchers badly. But it appears that Valve has now rolled out a patch to fix the two LPE flaws in Steam, and more importantly, has admitted that ignoring Kravets' first report was a mistake. Valve also noted that whole saga was due to a misunderstanding of its bug bounty rules.

Advertisement

“Our HackerOne program rules were intended only to exclude reports of Steam being instructed to launch previously installed malware on a user's machine as that local user. Instead, misinterpretation of the rules also led to the exclusion of a more serious attack that also performed local privilege escalation through Steam," Valve was quoted as saying by ZDNet. Additionally, the company behind Steam has updated the rules of its bug bounty program to avoid such incidents in the future. While Valve's rule change is reassuring, the victim researcher is still banned from the Steam bug bounty program run by HackerOne.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Valve. Steam, HackerOne
Advertisement
Popular Mobile Brands
  1. OnePlus N6 Lite 4G vs iQOO Z11 Lite vs Samsung Galaxy M17
  2. Lava Virat Curve vs Poco M8 Power vs Vivo T5 Lite:
  3. Best Gaming Phones Under Rs. 80,000 in India
  4. Samsung Galaxy S26 FE vs Oppo Find X9s vs Vivo V70 Elite Compared
  1. Magic Eden Investigates Possible Exploit After NFTs Move for 0 ETH
  2. Amazon Great Indian Festival 2026: Early Deals Are Now Live on OnePlus N6x, iQOO Z10 Lite 5G, and More
  3. Marking 12 Years of Make in India, Gov't Targets the Brains Inside Our Smartphones
  4. Google Photos Update Brings Redact Tool, Moods and AI Wardrobe
  5. Halo Studios Reportedly Has Around 30 Employees Left After Layoffs as Activision Takes Charge of Franchise
  6. KelpDAO Sues LayerZero Over $292 Million rsETH Exploit, Claims Bridge Risks Were Not Disclosed
  7. OpenAI Plans to Launch a New Cybersecurity-Focused GPT-6 Series AI Model: Report
  8. Vivo V80 Price in India Leaked Ahead of October 6 Launch: What You Need to Know
  9. Infinix GT NX Controller With Pixel-Level FPS Touchpad, GT NX Station Cooling Dock Unveiled
  10. Bitget Suffers $351.6 Million Security Breach, Exchange Says No Private Keys Were Leaked
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.