Sploitus

CVE-2020-15530

No indexed exploits for CVE-2020-15530 yet

An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMFILES(X86)%\Steam have weak permissions during a critical time window. An attacker can make this time window arbitrarily long by using opportunistic locks.

Affected products
Valve Steam Client
Valvesoftware Steam Client
= 2.10.91.91
CVSS 3.1
7.8 HIGH
EPSS
0.5% (44th percentile)
Weakness
CWE-362
NVD status
Modified
Published
2020-07-05
CVE-2020-15530 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-15530 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-15530 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.