CVE Database · CVE-2016-5237
CVSS v3.1
N/A
EPSS
0.78%
Published
Jan 23, 2017
Modified
May 12, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.
Weaknesses (CWE)
Affected Products (1)
References (4)