Valve Patches Zero Day Vulnerabilities in Steam After Banning Researcher Who Discovered Them, Changes Bug Bounty Rules

Valve has called banning of the security researcher a mistake.

Advertisement
By Nadeem Sarwar | Updated: 23 August 2019 16:16 IST
Highlights
  • Valve initially refused to recognise the LPE as a serious issue
  • The LPE flaws could be exploited to gain admin privilege
  • The security researcher who found the LPEs remains banned

Russian security researcher, Vasily Kravets, was prohibited from going public with his discovery

Valve recently attracted a lot of criticism from the cyber-security community after turning away a researcher who discovered a couple of zero-day vulnerabilities in Steam, and eventually blocked him from its bug bounty platform. Valve has now taken cognisance of the whole incident, and after patching the two potentially serious Local Privilege Escalation (LPE) vulnerabilities, the company has called the treatment meted out to the researcher a mistake and has also updated its bug bounty programme rules. What is worth noting is that the Valve partner handling it initially refused to recognise the zero-day flaw as a serious issue, prompting the security researcher to disclose it publicly.

Russian security researcher, Vasily Kravets, discovered a Local Privilege Escalation (LPE) issue in Steam and proceeded to file a bug report. HackerOne, the Valve partner overseeing the Steam bug bounty programme, called the report out of scope and pointed that Valve has no intentions to patch it. Additionally, they forbade Kravets from disclosing the issues publicly, leaving millions of Steam users vulnerable to a flaw that could enable a local malware to exploit the Steam app for gaining admin rights and eventually taking over the host.

However, the security researcher eventually went public with his discovery leading to him being banned from the bug bounty programme by HackerOne. And even though Valve later rolled out a patch to fix it, an alternative way to exploit it was soon discovered. To make matters worse, Kravets eventually discovered a second LPE vulnerability and published it on his own, since he was unable to file the bug report.

Advertisement

The whole saga painted a negative picture of Valve as a company that is reckless with security and handles such vulnerabilities in an irresponsible fashion, in addition to treating researchers badly. But it appears that Valve has now rolled out a patch to fix the two LPE flaws in Steam, and more importantly, has admitted that ignoring Kravets' first report was a mistake. Valve also noted that whole saga was due to a misunderstanding of its bug bounty rules.

Advertisement

“Our HackerOne program rules were intended only to exclude reports of Steam being instructed to launch previously installed malware on a user's machine as that local user. Instead, misinterpretation of the rules also led to the exclusion of a more serious attack that also performed local privilege escalation through Steam," Valve was quoted as saying by ZDNet. Additionally, the company behind Steam has updated the rules of its bug bounty program to avoid such incidents in the future. While Valve's rule change is reassuring, the victim researcher is still banned from the Steam bug bounty program run by HackerOne.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Valve. Steam, HackerOne
Advertisement
Popular Mobile Brands
  1. How to Reset Your Instagram Reels Algorithm
  2. Samsung Said to Ready 3.6 Million Galaxy S26 Ultra Units Ahead of Launch
  3. Google Might Be Making It Hassle-Free to Switch From ChatGPT to Gemini
  4. Oppo A6i+ 5G, A6v 5G With 50-Megapixel Cameras Launched at These Prices
  5. Xiaomi 17 Ultra Global Variant Price, Colourways and Battery Details Leaked
  6. The Game Awards 2026 Sets December 10 Date: Will GTA 6 Be Eligible?
  7. Samsung Galaxy S26 Ultra Appears in Leaked Poster in This New Colourway
  8. Sony WF-1000XM6 Price, Launch Timeline and Key Features Leaked
  1. Google to Reportedly Make Switching From ChatGPT to Gemini Hassle-Free
  2. Xiaomi 17 Ultra Global Variant Tipped to Launch With Smaller Battery; Price, Colour Options Leaked
  3. The Game Awards 2026 Sets December 10 Date: Will GTA 6 Be Eligible?
  4. Oakley Meta Vanguard Launched in India With Meta AI Integration: Price, Specifications
  5. Samsung to Produce 3.6 Million Galaxy S26 Ultra Units as Company Anticipates Increased Demand, Tipster Claims
  6. Samsung Galaxy S26 Ultra Appears in Leaked Promotional Poster With Redesigned Camera Island, New Colourway
  7. Google Disrupts Massive Proxy Network That Hijacked Millions of Smartphones, PCs for Cyberattacks
  8. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 and Galaxy Tab S12 Series Reportedly Listed on IMEI Database
  9. iQOO 15R Battery Capacity and Thickness Revealed Ahead of Launch in India
  10. Scientists Discover Cosmic Clock in Zircon Crystals That Tracks Earth’s Landscape History
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.