Vulnerability CVE-2019-17180


Published: 2019-10-04

Description:
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or unspecified other impact.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Valvesoftware -> Steam client 

 References:
https://amonitoring.ru/article/steam_vuln_3/
https://habr.com/ru/company/pm/blog/469507/
https://hackerone.com/reports/682774
https://store.steampowered.com/news/54236/

Copyright 2024, cxsecurity.com

 

Back to Top