Sploitus

CVE-2019-14743

2 known exploits for CVE-2019-14743

In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.

Affected products
Valve Steam Client
Valvesoftware Steam Client
≤ 2019-08-07
Fix
Available
CVSS 2.0
7.2 HIGH
CVSS 3.1
6.6 MEDIUM
EPSS
0.6% (47th percentile)
Weakness
CWE-732
NVD status
Modified
Published
2019-08-07
CVE-2019-14743 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2019-14743

Proof-of-concept code and exploit modules indexed by Sploitus