Second Steam Zero-Day Impacts Over 96 Million Windows Users
#1
Quote:A second Steam Windows client zero-day privilege escalation vulnerability affecting over 96 million users has been publicly disclosed today by Russian researcher Vasily Kravets.
 
This happens after Valve disputed the significance of the previous Steam 0day disclosed by Kravets on Twitter and banned him out of their HackerOne bug bounty program.
 
Seeing that this vulnerability impacts only the Steam Windows client, with Steam having over 100 million registered users and 96.28% of them are running Windows according to the Steam Hardware & Software Survey: July 2019, the systems of roughly 96 millions of them are currently affected. 
 
The privilege escalation (also known as an elevation of privilege or local privilege escalation) security flaw disclosed today by Kravets can allow attackers with limited rights to use a technique known as BaitAndSwitch to run executables using the Steam Client Service's  NT AUTHORITY\SYSTEM elevated permissions.
 
This would allow potential attackers to launch a three-stage attack, getting remote code execution privileges by exploiting a vulnerability in a Steam game, a Windows app, or the OS itself, subsequently elevating privileges on the compromised device and running a malicious payload using SYSTEM permissions.
 
As Kravets detailed in his write-up, "achieving maximum privileges can lead to much more disastrous consequences. For example, disabling firewall and antivirus, rootkit installation, concealing of process-miner, theft any PC user’s private data — is just a small portion of what could be done."

Read more here: https://www.bleepingcomputer.com/news/se...ows-users/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply
#2
Steam Patches LPE Vulnerabilities in Beta Version Update
Quote:Almost 48 hours after security researcher Vasily Kravets (PsiDragon) released his proof of concept (PoC) for a second vulnerability in Steam client for Windows leading to privilege escalation, Valve released a beta update that allegedly fixes the bugs.

Read more here: https://www.bleepingcomputer.com/news/se...on-update/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] Revo Registry Cleaner P...
OPTION 2 Share feed...zevish — 06:51
NVIDIA’s new DLSS Transformer model requ...
NVIDIA DLSS 310.3....harlan4096 — 10:09
INTEL Arc Graphics 32.0.101.6913 driver
Highlights  Int...harlan4096 — 10:07
AppCheck Anti-Ransomware 3.1.42.3
Version 3.1.42.3 (...harlan4096 — 10:06
AdGuard Browser Extension 5.1.113 (MV3 s...
AdGuard Browser Ex...harlan4096 — 10:03

[-]
Birthdays
Today's Birthdays
avatar (42)uapedDow
avatar (46)suiscced
avatar (47)Angarpaf
avatar (40)clarissalo60
Upcoming Birthdays
avatar (46)dapedDow
avatar (48)TromPerl
avatar (45)RidgeDimb
avatar (36)ipumaqar
avatar (50)tanliorsPeri
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (47)ConradRoand
avatar (38)boineDon
avatar (50)spoofTum
avatar (49)WillieVot
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (40)optsaZes
avatar (39)RaymondViata
avatar (39)ywixazok
avatar (37)ixoqe
avatar (55)Step 1
avatar (35)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>