vendor:
Steam
by:
gsX
N/A
CVSS
MEDIUM
Local Privilege Escalation
523
CWE
Product Name: Steam
Affected Version From: 3.42.16.13
Affected Version To: 3.42.16.13
Patch Exists: NO
Related CWE: CVE-2016-5237
CPE: cpe:2.3:a:valve:steam:3.42.16.13:*:*:*:*:*:*:*
Platforms Tested: Windows 7 Professional x64
2016
Valve Steam 3.42.16.13 Local Privilege Escalation
The Steam directory located at C:Program Files (x86)Steam implement weak file permissions and allow anyone in the BUILTINUsers windows group to modify any file in the Steam directory and any of its child files and folders. Since Steam is a startup application by default this makes it particularly easy to achieve lateral/vertical privilege escalation and achieve code execution against any user running the application.
Mitigation:
Valve was contacted on several occasions and given time to reply/fix the issue before releasing this entry.