It was recently reported that a recent Steam update carried a security patch aimed at addressing a vulnerability that had been present for 10 years.
Valve’s digital distribution platform, Steam, received a client update last March 21 to which more fixes were added the following month. Users might have thought that this was a regular update like the previous ones that arrived. But security researcher Tom Court revealed in a blog that the said client update had more importance to it than most Steam customers initially thought.
Reports picked up Court’s blog where it was explained that a remote code execution vulnerability had been lurking around the Steam Client for at least the last 10 years, exposing over 125 million users to a cyber disaster waiting to happen. Luckily, Valve already came up with a fix and Steam customers have fewer things to worry about as long as they have the latest version of the Steam Client.
In fact, Valve gave Court a shoutout in the patch notes of the March 21 client update. The company said: “Fixed a crash when packets in a UDP connection were malformed in a particular way. Thanks to Tom Court from Context Information Security for reporting this issue.”
In Court’s blog post, he explained, “At its core, the vulnerability was a heap corruption within the Steam client library that could be remotely triggered, in an area of code that dealt with fragmented datagram reassembly from multiple received UDP packets."
The security researcher also uploaded a video to show how the vulnerability could have been exploited. Simply put, had the security flaw been found by attackers, they could easily take control of a target’s computer. In Court’s sample, he showed how the vulnerability allowed him to remotely control a computer’s calculator software.
Meanwhile, Valve maintains that they did not find any indication that the decade-old security issue was exploited before they rolled out the needed patch.


Chinese Universities with PLA Ties Found Purchasing Restricted U.S. AI Chips Through Super Micro Servers
TSMC Japan's Second Fab to Produce 3nm Chips by 2028
Nanya Technology Shares Surge 10% After $2.5 Billion Private Placement from Sandisk and Cisco
NASA Artemis II: First Crewed Moon Mission Since Apollo Takes Four Astronauts on 10-Day Lunar Journey
Reflection AI Eyes $25 Billion Valuation in Massive $2.5 Billion Funding Round
OpenAI Pulls the Plug on Sora, Ending $1 Billion Disney Partnership
Annie Altman Amends Sexual Abuse Lawsuit Against OpenAI CEO Sam Altman
Microsoft Eyes $7B Texas Energy Deal to Power AI Data Centers
SK Hynix Eyes Up to $14 Billion U.S. IPO to Fund AI Chip Expansion
Google's TurboQuant Algorithm Sends Memory Chip Stocks Tumbling
Nintendo Switch 2 Production Cut as Holiday Sales Miss Targets
Makemation: a Nollywood movie that shows AI in action in Africa
California's AI Executive Order Pushes Responsible Tech Use in State Contracts
Rubio Directs U.S. Diplomats to Use X and Military Psyops to Counter Foreign Propaganda
Federal Judge Blocks Pentagon's Blacklisting of AI Company Anthropic
Elon Musk Announces Terafab: SpaceX and Tesla to Build Dual AI Chip Factories in Austin, Texas
SpaceX Eyes Historic IPO at $1.75 Trillion Valuation 



