Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Valve Steam Client for Windows 权限许可和访问控制问题漏洞
Vulnerability Description
Valve Steam是美国Valve公司的一套游戏发行管理平台。该平台提供数字版权管理、多人游戏、流媒体和社交网络服务等功能。 基于Windows平台的Valve Steam Client 2019-08-20及之前版本中存在权限许可和访问控制错误漏洞。攻击者可通过使用CreateMountPoint.exe和SetOpLock.exe文件利用该漏洞将权限提升至NT AUTHORITYSYSTEM。
CVSS Information
N/A
Vulnerability Type
N/A