Steam had a decade-old security flaw that could allow someone to take over your PC

Steam logo

Sometimes, vulnerabilities can hang around for years and years without being discovered, and a remote code execution flaw found in Steam has reportedly been a gaping hole in the side of Valve’s gaming service for no less than a decade – although it has now been patched.

As Motherboard reports, Tom Court, a security expert at Context, believes that the exploit had been present in Steam for at least 10 years, and every user of the service could potentially have had this leveraged against them during that period.

However, as we mentioned, the good news is that the exploit has already been patched by Valve, and in fact this particular vulnerability was fixed back in March.

How serious was the problem? Court describes the bug as ‘simple’ and ‘straightforward to exploit’, worryingly, and the vulnerability could potentially have allowed a malicious party to execute code on the target PC running Steam, subsequently letting them take control of the machine.

So, yeah. It was pretty serious, then.

Speedy response

On the positive side for Valve, this vulnerability was made harder to exploit last July when the firm implemented a new security measure: ASLR (address space layout randomization).

But it was still a potential hole until Court reported the problem to Valve, with the company also being quick to respond – he praised the firm for the fact that within eight hours of receiving his email, it had applied a fixed to the beta version of the Steam client.

Court concludes that the code in which the vulnerability resided was likely very old, and the developers probably hadn’t been anywhere near it in a long time as a result.

The lesson? Software developers should take the time to review old chunks of code in the light of contemporary security standards, probing for issues such as this which may have been hanging around for ages.

Generally speaking, there are probably a host of these sort of flaws scattered about the world of PC software, when you consider the sheer amount of apps and services out there. The worry is that if developers or a friendly white hat security researcher don’t find them first, they could be actively exploited against an entire user base.

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in PC Gaming
Image of Naoe in AC Shadows
Assassin's Creed Shadows is hands-down one of the most beautiful PC ports I've ever seen
Image of AC Shadows cover art & Steam Deck
It's not perfect, but Assassin's Creed Shadows' performance is impressive - it runs smoothly on the Steam Deck and Asus ROG Ally
Asus ROG Ally using Steam
I think Asus could be the perfect partner for an Xbox handheld – but I have questions
Playing games on the Razer Handheld Dock Chroma without an external display.
The Razer Handheld Dock Chroma offers Steam Deck owners a premium design and, of course, plenty of RGB
Image of GTA 6 protagonists and PS5
GTA 6's console-only launch reminds me of how much I despise console exclusivity - is it worth waiting years for PC ports?
Image of Grand Theft Auto 6 promotional art and Corsair's PC cases
GTA 6 could reach PCs in early 2026 according to Corsair – but I'm already sick of waiting
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)