Vulnerability Description
An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMFILES(X86)%\Steam have weak permissions during a critical time window. An attacker can make this time window arbitrarily long by using opportunistic locks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Valvesoftware | Steam Client | 2.10.91.91 |
Related Weaknesses (CWE)
References
- http://daniels-it-blog.blogspot.com/2020/07/steam-arbitrary-code-execution-part-ExploitThird Party Advisory
- http://daniels-it-blog.blogspot.com/2020/07/steam-arbitrary-code-execution-part-ExploitThird Party Advisory
FAQ
What is CVE-2020-15530?
CVE-2020-15530 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMF...
How severe is CVE-2020-15530?
CVE-2020-15530 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15530?
Check the references section above for vendor advisories and patch information. Affected products include: Valvesoftware Steam Client.