CVE-2021-30481 is a critical buffer overflow vulnerability affecting Valve Steam clients prior to April 17, 2021, specifically when a Source engine game is installed. This flaw allows remote authenticated attackers to execute arbitrary code with a single click on a malicious Steam invite. Rated 9.0 Critical (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H), it indicates a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. While not listed in CISA KEV or having public Metasploit/Nuclei exploits, its high FAUCET Risk Score of 95/100, significant community discussion (more than 99% of all CVEs), and media coverage suggest considerable attention and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021-04-10CPE matchmatch criteria | cpe:2.3:a:valvesoftware:steam_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.