Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Second Steam Zero-Day Impacts Over 96 Million Windows Users
#1
Quote:A second Steam Windows client zero-day privilege escalation vulnerability affecting over 96 million users has been publicly disclosed today by Russian researcher Vasily Kravets.

This happens after Valve disputed the significance of the previous Steam 0day disclosed by Kravets on Twitter and banned him out of their HackerOne bug bounty program.

Seeing that this vulnerability impacts only the Steam Windows client, with Steam having over 100 million registered users and 96.28% of them are running Windows according to the Steam Hardware & Software Survey: July 2019, the systems of roughly 96 millions of them are currently affected. 


The privilege escalation (also known as an elevation of privilege or local privilege escalation) security flaw disclosed today by Kravets can allow attackers with limited rights to use a technique known as BaitAndSwitch to run executables using the Steam Client Service's  NT AUTHORITY\SYSTEM elevated permissions.

This would allow potential attackers to launch a three-stage attack, getting remote code execution privileges by exploiting a vulnerability in a Steam game, a Windows app, or the OS itself, subsequently elevating privileges on the compromised device and running a malicious payload using SYSTEM permissions.

As Kravets detailed in his write-up, "achieving maximum privileges can lead to much more disastrous consequences. For example, disabling firewall and antivirus, rootkit installation, concealing of process-miner, theft any PC user’s private data — is just a small portion of what could be done."

Continue reading HERE
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Over 10 Million Facebook Users Hacked in Ongoing Phishing Scam mrtrout 2 1,052 05-29-2023 , 03:41 PM
Last Post: Kai Brooks
  Hacker group claims to steal 3 million users’ data from Israeli hiking websites mrtrout 0 1,015 01-22-2022 , 11:03 PM
Last Post: mrtrout
  Customized Trojan Stole Data From 3M Windows PC Users mrtrout 0 701 07-02-2021 , 05:51 AM
Last Post: mrtrout
  533 million Facebook users' phone numbers and personal data have been leaked online SALAMA Youssef 0 1,370 04-04-2021 , 09:47 PM
Last Post: SALAMA Youssef
  Data Loss Impacts 40% of SaaS App Users Bjyda 0 902 03-28-2021 , 09:09 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)