CVE-2019-15316
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.
- Affected products
- Valve Steam Client
- Valvesoftware Steam Client
- ≤ 2019-08-20
- Fix
- Available
- CVSS 3.0
- 7.0 HIGH
- EPSS
- 0.4% (37th percentile)
- Weakness
- CWE-367, CWE-732
- NVD status
- Modified
- Published
- 2019-08-21
CVE-2019-15316 at NVD
No indexed exploits for CVE-2019-15316 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-15316 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.