Vulnerability Description
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Valvesoftware | Steam Client | <= 2019-08-16 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://xiaoyinl.github.io/steam_EoP_bypass.htmlThird Party Advisory
- https://xiaoyinl.github.io/steam_EoP_bypass.htmlThird Party Advisory
FAQ
What is CVE-2019-15315?
CVE-2019-15315 is a vulnerability with a CVSS score of 7.8 (HIGH). Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll wit...
How severe is CVE-2019-15315?
CVE-2019-15315 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15315?
Check the references section above for vendor advisories and patch information. Affected products include: Valvesoftware Steam Client, Microsoft Windows.