CVE-2016-5237

MEDIUM

Valvesoftware Steamos < 3.42.16.13 - Access Control

Title source: rule
STIX 2.1

Description

Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.

Exploits (1)

exploitdb WRITEUP
by Gregory Smiley · textlocalwindows
https://www.exploit-db.com/exploits/39888

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/39888/

Scores

CVSS v3 4.8
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-264
Status published
Products (1)
valvesoftware/steamos < 3.42.16.13
Published Jan 23, 2017
Tracked Since Feb 18, 2026