PT-2019-13811 · Valve · Valve Steam Client

Xi-Tauw

·

Published

2019-08-07

·

Updated

2020-08-24

·

CVE-2019-14743

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Valve Steam Client for Windows versions prior to 2019-08-07
Description The issue allows local users to gain NT AUTHORITYSYSTEM access due to explicit "Full control" for the Users group in the HKLMSOFTWAREWow6432NodeValveSteam registry key.
Recommendations For versions prior to 2019-08-07, consider restricting access to the HKLMSOFTWAREWow6432NodeValveSteam registry key to prevent local users from gaining elevated privileges.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14743

Affected Products

Valve Steam Client