Vulnerability Description
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Valvesoftware | Steam Client | <= 2021-04-10 |
Related Weaknesses (CWE)
References
- https://news.ycombinator.com/item?id=26762170Issue TrackingThird Party Advisory
- https://twitter.com/floesen_/status/1337107178096881666Third Party Advisory
- https://twitter.com/the_secret_club/status/1380868759129296900ExploitThird Party Advisory
- https://www.youtube.com/watch?v=rNQn--9xR1QExploitThird Party Advisory
- https://news.ycombinator.com/item?id=26762170Issue TrackingThird Party Advisory
- https://twitter.com/floesen_/status/1337107178096881666Third Party Advisory
- https://twitter.com/the_secret_club/status/1380868759129296900ExploitThird Party Advisory
- https://www.youtube.com/watch?v=rNQn--9xR1QExploitThird Party Advisory
FAQ
What is CVE-2021-30481?
CVE-2021-30481 is a vulnerability with a CVSS score of 8.0 (HIGH). Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one...
How severe is CVE-2021-30481?
CVE-2021-30481 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30481?
Check the references section above for vendor advisories and patch information. Affected products include: Valvesoftware Steam Client.