First published: Wed Aug 07 2019(Updated: )
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Steam Client | <=2019-08-07 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14743 is a vulnerability found in the Valve Steam Client for Windows, which allows local users to gain NT AUTHORITY\SYSTEM access.
CVE-2019-14743 has a severity rating of 6.6, which is considered high.
CVE-2019-14743 affects Valve Steam Client for Windows versions up to and including 2019-08-07.
Local users can exploit CVE-2019-14743 to gain NT AUTHORITY\SYSTEM access.
There are no available fixes for CVE-2019-14743 at the moment. It is recommended to update Valve Steam Client to the latest version when a fix becomes available.