Jump to content

Hackers Hijacked PCs Using Source Engine Kill Animation Exploit


Quicksilver

Recommended Posts

Counter-Strike: Global Offensive, Team Fortress 2, Portal 2 and other Source Engine games were all affected by a particularly nasty exploit until recently. Basically, by uploading custom assets into a custom map, hackers could use them to trigger a "buffer overflow vulnerability" which resulted in the victim PC being open to remote code execution.

In other words, merely shooting at an enemy could cause your machine to be remotely hijacked. The exploit was identified by One Up Security (via Motherboard) who notified Valve.

"Valve's Source SDK contained a buffer overflow vulnerability which allowed remote code execution on clients and servers," OUP's statement reads. "The vulnerability was exploited by fragging a player, which caused a specially crafted ragdoll model to be loaded.

Multiple Source games were updated during the month of June 2017 to fix the vulnerability. Titles included CS:GO, TF2, Hl2:DM, Portal 2, and L4D2. We thank Valve for being very responsive and taking care of vulnerabilites swiftly. Valve patched and released updates for their more popular titles within a day."

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use. We also recommend reading our Privacy Policy and Guidelines.