CVE-2019-14743

CVE-2019-14743

** DISPUTED ** In Valve Steam Client for Windows through 2019-08-07, HKLMSOFTWAREWow6432NodeValveSteam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITYSYSTEM access. NOTE: the vendor disputes the significance of this finding; the discoverer was reportedly told that the Steam threat model excludes "Attacks that require physical access to the user’s device" and "Attacks that require the ability to drop files in arbitrary locations on the user’s filesystem" (which might apply to the attacker’s ability to create links under HKLMSOFTWAREWow6432NodeValveSteamApps).

Source: CVE-2019-14743

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다