A vulnerability in Valve’s Source SDK allows a malicious actor to execute code on a user’s computer. The vulnerability is a simple buffer overflow in the Source SDK, a library used by game vendors to support custom mods and other features. Source engine map files also allow developers to pack custom content to be loaded with a custom map. Multiple Source games were updated during the month of June 2017 to fix the vulnerability, such as CS:GO, TF2, Hl2:DM, Portal 2, and L4D2.
Source: https://www.bleepingcomputer.com/news/security/valve-patches-security-flaw-that-allows-installation-of-malware-via-steam-games/

