Get a Pentest and security assessment of your IT network.

Cyber Security

Steam Patches LPE Vulnerabilities in Beta Version Update

Security researcher Vasily Kravets (PsiDragon) released a proof of concept (PoC) for a second vulnerability in Steam client for Windows leading to privilege escalation. The vulnerability could be exploited using a command prompt window running with SYSTEM account privileges, the highest for a user on Windows. A few days later, Valve published a patch for the vulnerability, but could be easily bypassed by a way around the fix. On August 20, another researcher discovered another LPE in the Steam client, but he could not report it because after publishing his previous zero-day, he had been banned from Valve’s HackerOne bug bounty program.

Source: https://www.bleepingcomputer.com/news/security/steam-patches-lpe-vulnerabilities-in-beta-version-update/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security