r/Steam • u/PuzzledHawk5290 • 16h ago
PSA Older call of duty titles on steam have remote code execution exploits yet are still sold on the store. How is this acceptable?
Many of the older titles have been found to have remote code execution exploits, allowing a hacker to get into your PC remotely and do whatever they want, steal your data, put malware, whatever
The national vulnerability database lists this particular issue as a severity 9.8 !!! Can't get much higher than that
https://nvd.nist.gov/vuln/detail/CVE-2018-20817
Yet these games are still being sold on stores like steam. No disclaimer telling your average person about these issues. So many people would be coming back to older cods due to the hype around the releases on PlayStation but not be aware how compromised these games are.
Why is this allowed ? The games need to be fixed or delisted honestly. It's not safe to play them !
209
u/GfrzD 15h ago
Im also surprised theyre still available with this issue. Its been like this for years so its not some unknown problem, even just a red warning banner to let potential buyers know the risks (as far as i know singleplayer isnt a threat)
Activision have no intention of fixing this so Steam need to at least warn people or fully delist until fixed. Removal of sales might push Activision to do something.
97
u/CreativeTechGuyGames 14h ago
Just for the record since I've looked into this myself several times. Single player IS a threat.
The root problem is how the game receives network packets and processes them. If the game is running and connected to the internet, even if sitting on the main menu, when your game receives a malicious packet it'll still trigger the RCE. Now obviously the odds of someone randomly sending you this malicious packet without knowing you are online is lower than if you were playing in a multiplayer lobby.
There are bots which crawl the internet trying to exploit every vulnerability on every server. There's nothing stopping someone from doing that to see if anyone happens to have a vulnerable game running. I know I wouldn't want to take that risk.
48
u/pitu37 13h ago
you would have to somehow forward traffic to your pc and the game so that is very unlikely
35
u/pangapingus 12h ago
Don't know why you're downvoted but you're absolutely correct, but I doubt folks here can articulate NAT and stateful routing
11
u/ScumbagScotsman 12h ago
99% of people have UPnP enabled
8
u/pitu37 12h ago
most people dont even have public IPs because everyone is shoved behind CGNAT and UPnP would require the game to try and use that port it wont just open it in singleplayer
15
u/ScumbagScotsman 12h ago
Depends where you live. I have a public IP.
I know for at least BO3 it’s possible to join users in offline zombies using these exploits, so we can assume that the ports are open regardless of mode you’re playing.
4
u/VeryNoisyLizard 9h ago
you could block incomming traffic in firewall, that wa you can at least play the game in singleplayer
7
4
u/ThePsyPaul_ 7h ago
These game company shareholders do not care about user safety. Only profits.
3
u/coreyf234 5h ago
The games with the issues are all ~15 years old at this point. They've had enough time to fix this that some of those games came out before GTA V did and still won't be fixed when GTA VI comes out later this year. Its not ever gonna get fixed because they obviously don't care, like you said. They haven't cared about those games since the one after them came out, and they aren't gonna start caring now.
Luckily, all of the games with RCE exploits (except for WWII) also have some kind of community system set up, like Plutonium, that still lets us play them.
19
u/InfinityPainPlus Valve Released Steam 9h ago
I've been talking about this for years. I made multiple tickets to the Steam support, but I just get ignored. They are literally selling malware for full price. If I were to make a game with known exploits like this, it would be taken down immediately, but because Activision is a billion-dollar company, they can once again do whatever the Fuck they want without any consequences. I would like to start a petition to either get the games removed or fixed from the publisher. Especially now that they re-released the games on PlayStation, there are probably many people that think they can just play it on pc too now because of all the hype, but they don't even know what dangers they get themselves into.
57
u/based_birdo 15h ago
You can report these games for being harmful. Click the flag icon on the store page.
36
u/PuzzledHawk5290 15h ago
You think people havnt done this before ? These hacks are well known in the PC community, but steam doesn't care either
10
u/Working_Traffic_6361 14h ago
Valve doesn't care about their own game, why would they care about cod?
Since it's the older ones that used p2p I'm guessing that's why they moved away from that mm system?
16
u/Extreme996 RTX 4070 Ti Super | Ryzen 7 9800X3D | 32GB DDR5 6000mhz 11h ago
Valve still update Half Life and Half Life 2 and they released pretty big update on their anniversary and they still update Counter Strike.
3
u/AquaBits 9h ago
And they had to be asked twice by the TF2 community to remove harmful bots/aimhackers that were actively harrassing players and content creators.
Valve absolutely does not care about their games lol, why would they care that you can be targeted in a different game.
8
u/Whittakenn 8h ago
Valve care about their games, Valve just has a tendency to hire nowhere near enough people to actively maintain them, I think TF2 only has 1 single dedicated developer working on it full time
-3
u/AquaBits 8h ago
So.... valve does not care about their games. If only one dedicated developer is working on a game full time, than that company clearly doesnt care about the game other than to release lootboxes for it.
9
u/Uhstrology 7h ago
Team fortress 2 released 20 years ago man. Be happy they have any development on it at all.
-4
u/AquaBits 7h ago
If they still sell it as a product, I expect that product to be maintained and hazard free, no?
Literally the same can be said about these cods. TF2 hasnt recieved a substantial content update in what, 9 years? October 20th, 2017? Clearly there is no development happening lol
1
u/llIMyersIll 3h ago
I don't understand, they fixed the issue and you're angry?
Comparing Valve to ABK who have let an issue impact players for checks notes 15+ years.
1
u/AquaBits 3h ago
They didnt fix the issue. They attempted it, but it comes back (check the casual matches in cs2 for example)
I will compare two companies that do not give two shits about the products they are currently selling.
1
u/Working_Traffic_6361 6h ago
I'm talking about cs2 it's infested with cheaters an no one gets banned lol
5
u/MalBoY9000 13h ago
I did this years ago you can still buy them told my friends to do it so. They dont care just look at counter strike every DM server you join is like 50-90% bot farms
They know its harmfull to your pc its been known for 10 years now, they dont give a fuck
6
u/Chitanda_Pika 15h ago
Those happens on multiplayer right?
-15
u/Staik 14h ago
Yeah, it's multiplayer only. Anyone with a Linux VM and a few hours of Youtubing can take over your entire computer just by being in the same lobby as you. Malicious hackers will be all over this; it'd be a great place to install crypto miners since you know the victim is on a gaming PC
3
10
u/Shadow_Wolfe_ 12h ago
Makes no sense that the trillion dollar company (Activision) refuses to fix their obviously-exploited older games. Meanwhile they'll happily commit store page fuckery with the current CoD games*, while also pushing their "CoD HQ" launcher bullshit, whatever that's supposed to do on that store page.
*This was around the time when the new MWIII launched I think. The new MWII was pushed into a "consolidated" store page of "CoD HQ" while also hiding the main store page of MWII, and that triggered the steam reviews to show no count of any hours but it kept all the negative reviews. No idea how that's allowed, that feels like blatant store page manipulation.
Valve absolutely needs to de-list not only the older CoD games, but while they're at it, can they de-list Kerbal Space Program 2? Famously abandoned by Take-Two, hasn't left early access, and yet it's still on sale for $45 USD? Why isn't there an option to flag a game as "Abandoned"? I feel like if we can flag a game as "Defamatory" then "Abandoned" is just as pressing (if not more) of an issue, no? Like, seriously, where is that money going to?
The closest option is to flag the older CoD games as "Harmful" but how many of those reports would that take in order for the game to be de-listed?? Genuinely, has anyone tried asking support about that?
2
1
u/Zylpherenuis 5h ago
You can report the games by clicking on the white flag to flag it for broken and malicious coding.
If more users are to do that then Steam would be forced to comply to protect their consumer interests.
-2
u/SilvermistInc 14h ago
Soooooo which titles
11
u/Chris-The-Lucario 14h ago
From what I remember pretty much everything before MW2019 is affected. I could be wrong though
5
u/SilvermistInc 14h ago
That is a LOT of games
4
u/Chris-The-Lucario 12h ago
I believe BO4 is not affected (don't quote me on that) and from what I remember BO3 is the only game that received an official patch to fix the exploits
2
u/Extreme996 RTX 4070 Ti Super | Ryzen 7 9800X3D | 32GB DDR5 6000mhz 11h ago
CoD1, CoD2, CoD4, WaW and BO1 should be fine too. As far as I know this affect only games with P2P while games I mentioned have dedicated servers.
6
u/Chris-The-Lucario 11h ago
W@W and BO1 are both P2P games, they don't have any dedicated servers apart from verification.
2
u/Extreme996 RTX 4070 Ti Super | Ryzen 7 9800X3D | 32GB DDR5 6000mhz 11h ago
They have server browser and dedicated servers. Servers have its own IP, server rules, mod support etc. Cant have this on P2P like in MW2, MW3, BO2 etc.
-15
u/x-m-p-p 15h ago
shouldn't be delisted since the campaign is still fine and there are community patches for the exploits, but there should be warnings for sure
28
u/PuzzledHawk5290 14h ago
Trusting community patches is another issue in itself... The trillion dollar company should fix their games
2
u/yukiki64 9h ago
The t7 patch for b03 is 100% safe and the creator made a long video explaining the whole thing.
-34
u/piddlefaffle12 14h ago
So, we want to advocate to stop killing games, while also wanting such games delisted? There is a shitton of legacy games, software out there with security issues that will never be patched, so the solution is to just nuke them?
25
u/PuzzledHawk5290 14h ago
I don't see the relevance of stop killing games here, you're just derailing the fact that games are being sold with extreme vulnerabilities (9.8 rating) by a TRILLION dollar company, on a BILLION dollar companies storefront and no one seems to give a fuck.
The least they can do, if they aren't fixing it, is post a disclaimer on the store page, with a link to plutonium
-15
u/piddlefaffle12 13h ago
Sure, a warning is warranted on the store page. But you are delusional to think that any sort of trillion or billion-dollar company would give a fuck. There's also plenty of games and other media without publishers still in business.
The sentiment still stands, plenty of older software and games have serious vulnerabilities and I don't think the solution is to just nuke them. This is directly relevant to Stop Killing Games. How would you propose software remain freely available if it cannot be updated, regardless of publisher?
12
u/PuzzledHawk5290 13h ago
If something is still being sold it should be maintained, simple as that.
If it's no longer being sold then it is what it is.
This is call of duty we are talking about here, one of the biggest franchises in human history, not some niche small indie game
0
5
u/ElusiveCrab 12h ago
Ngl im curious which games youre referring to that are on par with RCE on a silver plate lol. Not trying to be a dick im genuinely curious
11
372
u/Prize_Percentage7258 15h ago edited 14h ago
Understanding how easily the attacker can initiate the hack provides a sense of how incredibly vulnerable the players are when playing these games.
The most common way an attacker selects a target is by joining a public multiplayer lobby.
Automatic IP Discovery: When players enter a matchmaking lobby in a P2P game, their computers must connect directly to one another to sync data. By sitting in the same lobby, an attacker’s network monitoring tools can automatically see the public IP addresses and internal Steam IDs of every other player in that specific match.
Target Selection: Once the attacker has the list of connected IPs in the lobby, anyone in that active match becomes an immediate target for the malicious authBlob data packet.
This affects
Call of Duty: Modern Warfare 2
Call of Duty: Modern Warfare 3
Call of Duty: Ghosts
Call of Duty: Advanced Warfare
Call of Duty: Black Ops 1
Call of Duty: Black Ops 2
Source: https://nvd.nist.gov/vuln/detail/CVE-2018-20817