Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x7v3-vhf3-7wrh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.

EPSS

Процентиль: 16%
0.00051
Низкий

Связанные уязвимости

CVSS3: 7
nvd
больше 6 лет назад

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.

EPSS

Процентиль: 16%
0.00051
Низкий