vendor:
Steam
by:
AbsoZed
8.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Steam
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Steam Privilege Escalation
This exploit is a privilege escalation vulnerability in Steam Client Service. It allows an attacker to gain SYSTEM privileges by replacing the ImagePath registry key of the msiserver service with a malicious payload. The malicious payload is then executed with SYSTEM privileges.
Mitigation:
Ensure that the Steam Client Service is not running with SYSTEM privileges. Also, ensure that the msiserver service is not running with SYSTEM privileges.