VendorsValve Softwaresteam_client2.10.91.91
Vulnerabilities

Valve Software Steam Client 2.10.91.91

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-15530
An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMFILES(X86)%\Steam have weak permissions during a critical time window. An attacker can make this time window arbitrarily long by using opportunistic locks.
Published 2020-07-05 · Modified
7.8EPSS 0.005
CVE-2015-7985
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.
Published 2015-11-24 · Modified
7.21 PoCEPSS 0.010