Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-08-21T19:36:06
Updated: 2024-08-05T00:42:03.701Z
Reserved: 2019-08-21T00:00:00
Link: CVE-2019-15316
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-08-21T20:15:12.930
Modified: 2024-11-21T04:28:26.183
Link: CVE-2019-15316
Redhat
No data.