CVE Vulnerabilities

CVE-2016-5237

Published: Jan 23, 2017 | Modified: Apr 20, 2025
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.

Affected Software

NameVendorStart VersionEnd Version
SteamosValvesoftware*3.42.16.13 (including)

References