First published: Mon Jan 23 2017(Updated: )
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Valve Software SteamOS | <=3.42.16.13 | |
<=3.42.16.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5237 is classified as a high severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2016-5237, ensure that file permissions in the Steam program directory are configured to restrict unauthorized access.
CVE-2016-5237 affects users of Valve Software's SteamOS version 3.42.16.13 and earlier.
CVE-2016-5237 facilitates local users to modify Steam files, potentially allowing them to execute malicious code with elevated privileges.
CVE-2016-5237 cannot be exploited remotely as it requires local access to the system to take advantage of the weak file permissions.