CVE-2019-15316
low-risk
Published 2019-08-21
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.
Do I need to act?
-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.0/10
High
LOCAL
/ HIGH complexity
Affected Products (1)
Steam Client
Affected Vendors
References (8)
Third Party Advisory
https://amonitoring.ru/article/onemore_steam_eop_0day/
Third Party Advisory
https://habr.com/ru/company/pm/blog/464367/
Third Party Advisory
https://amonitoring.ru/article/onemore_steam_eop_0day/
Third Party Advisory
https://habr.com/ru/company/pm/blog/464367/
23
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal