A security researcher discovered a bug that allowed an attacker to execute malicious code on Steam’s 15 million gaming clients. The root cause of the bug is a buffer overflow in one of Steam’s internal libraries. An attacker was only required to send malformed UDP packets to a target’s Steam client, which would have triggered the bug and allowed him to run malicious code. The bug was accidentally half-patched last July, when Valve added ASLR protection to the Steam desktop client. The added security feature made exploitation more difficult.
Source: https://www.bleepingcomputer.com/news/security/valve-patches-security-bug-that-existed-in-steam-client-for-the-past-ten-years/