CVE Vulnerabilities

CVE-2016-5237

Published: Jan 23, 2017 | Modified: Sep 07, 2017
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.

Affected Software

Name Vendor Start Version End Version
Steamos Valvesoftware * 3.42.16.13 (including)

References