Overclock.net › Forums › Industry News › Software News › [TS] Security researchers discover vulnerability in Steam URL protocol
New Posts  All Forums:Forum Nav:

[TS] Security researchers discover vulnerability in Steam URL protocol

post #1 of 3
Thread Starter 
Quote:
Security researchers from ReVuln have discovered a zero-day vulnerability in Valve’s Steam browser protocol. The exploit can allow an attacker to remotely exploit bugs in the Steam client or directly in games which can ultimately be used to run malicious code on the target PC.

Researchers point out that when Steam is installed on a computer, it is registered as a steam:// URL protocol handler. This allows the gaming client to automatically handle all steam:// URLs that a user clicks in a browser.

Valve developed the protocol to be used in places such as the Steam Web Store to perform various tasks like installing or uninstalling a game, updating titles or even launching a game with special parameters.

Source

Basically be wary of carelessly clicking Steam:// URL links from untrusted sources online to stay safe until Valve patches the vulnerability.
post #2 of 3
Thanks, good to know.
Ex-Kentsfield rig
(20 items)
 
Q6600 RIG :D
(9 items)
 
 
CPUMotherboardGraphicsRAM
4790k MSI Z97M Gaming 780 Ti SLi Corsair Vengeance pro 2x8GB 
Hard DriveHard DriveCoolingOS
Seagate NAS 240GB m500s RAID 0 MCP 350 w/ res top >> MCP655 >> Heatkiller full... Windows 8.1 
MonitorKeyboardPowerCase
3X QNIX 2560x1440 @ 110Hz G910 EVGA Supernova 1000 G2 Stacker 830 
MouseMouse PadAudioAudio
G402 / Deathadder 2K13 League of legends one, cloth ODAC >> O2 >> HD800 / K702s Samson mediaone 5as 
AudioOtherOtherOther
Samson GoMic Asus wireless AC Logitech G27 Logitech C920 Webcam 
CPUMotherboardGraphicsRAM
Q6600 Asus P5Q-E 8800GTX Crucial Ballistix Tracers 
Hard DriveCoolingOSPower
320GB Samsung spintpoint T166 Xigmatek Dark Knight 7 Chieftec 390W :p 
Case
Some generic chieftec one for now 
  hide details  
Reply
Ex-Kentsfield rig
(20 items)
 
Q6600 RIG :D
(9 items)
 
 
CPUMotherboardGraphicsRAM
4790k MSI Z97M Gaming 780 Ti SLi Corsair Vengeance pro 2x8GB 
Hard DriveHard DriveCoolingOS
Seagate NAS 240GB m500s RAID 0 MCP 350 w/ res top >> MCP655 >> Heatkiller full... Windows 8.1 
MonitorKeyboardPowerCase
3X QNIX 2560x1440 @ 110Hz G910 EVGA Supernova 1000 G2 Stacker 830 
MouseMouse PadAudioAudio
G402 / Deathadder 2K13 League of legends one, cloth ODAC >> O2 >> HD800 / K702s Samson mediaone 5as 
AudioOtherOtherOther
Samson GoMic Asus wireless AC Logitech G27 Logitech C920 Webcam 
CPUMotherboardGraphicsRAM
Q6600 Asus P5Q-E 8800GTX Crucial Ballistix Tracers 
Hard DriveCoolingOSPower
320GB Samsung spintpoint T166 Xigmatek Dark Knight 7 Chieftec 390W :p 
Case
Some generic chieftec one for now 
  hide details  
Reply
post #3 of 3
I didn't even know there was a Steam:// URL link.
Millenium Falcon
(24 items)
 
  
CPUMotherboardGraphicsRAM
Core i7 4930k MSI Big Bang Xpower II EVGA GTX 690 Patriot Viper II Sector 7 
Hard DriveHard DriveHard DriveHard Drive
OCZ Deneva 2 Corsair Force 3 Maxtor Western Digital Green 
Optical DriveCoolingCoolingCooling
Samsung BD/DVD-RW Swiftech MCP655 x2 Black Ice GTX 480 Black Ice GTX 280 
CoolingCoolingCoolingCooling
Alphacool Repack Dual D5 Watercool Heatkiller 3.0 Alphacool GTX 690 fullcover Bitspower Big Bang Xpower II fullcover 
OSMonitorKeyboardPower
Windows 8.1 64-bit Professional 3x Dell S2340 Max Keyboard Durandal CoolerMaster V1000 
CaseMouseMouse PadAudio
Azza Genesis 9000B Logitech G700 Roccat Alumic Onkyo HT-S9100THX 
  hide details  
Reply
Millenium Falcon
(24 items)
 
  
CPUMotherboardGraphicsRAM
Core i7 4930k MSI Big Bang Xpower II EVGA GTX 690 Patriot Viper II Sector 7 
Hard DriveHard DriveHard DriveHard Drive
OCZ Deneva 2 Corsair Force 3 Maxtor Western Digital Green 
Optical DriveCoolingCoolingCooling
Samsung BD/DVD-RW Swiftech MCP655 x2 Black Ice GTX 480 Black Ice GTX 280 
CoolingCoolingCoolingCooling
Alphacool Repack Dual D5 Watercool Heatkiller 3.0 Alphacool GTX 690 fullcover Bitspower Big Bang Xpower II fullcover 
OSMonitorKeyboardPower
Windows 8.1 64-bit Professional 3x Dell S2340 Max Keyboard Durandal CoolerMaster V1000 
CaseMouseMouse PadAudio
Azza Genesis 9000B Logitech G700 Roccat Alumic Onkyo HT-S9100THX 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Software News
Overclock.net › Forums › Industry News › Software News › [TS] Security researchers discover vulnerability in Steam URL protocol