vendor:
Steam Client Application
by:
Gjoko 'LiquidWorm' Krstic
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Steam Client Application
Affected Version From: Built: Jun 1, 2011 at 15:31:24, Steam API: v010, Steam package versions 1559 / 1559, File version: 1.0.968.628
Affected Version To: Built: Jun 1, 2011 at 15:31:24, Steam API: v010, Steam package versions 1559 / 1559, File version: 1.0.968.628
Patch Exists: NO
Related CWE: N/A
CPE: a:valve:steam_client_application
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2011
Valve Steam Client Application v1559/1559 Local Privilege Escalation
Steam is vulnerable to an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for the 'Users' group, for the binary file Steam.exe, GameOverlayUI.exe and steamerrorreporter.exe. The binary (Steam.exe) is set by default to Startup with '-silent' parameter.
Mitigation:
Ensure that the permissions for the Steam.exe, GameOverlayUI.exe and steamerrorreporter.exe binaries are properly set and that only authorized users have access to them.