Steam Client

Vendor:

First CVE: May 20, 2015 · Active for 11 years

9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Steam Client over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 20, 2015
11 years ago
Most Recent CVE
Apr 10, 2021
1,932 days ago

CVE Severity & Scoring

Steam Client9 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local4 (44.4%)
Network2 (22.2%)
Unknown2 (22.2%)
Physical1 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High1 (11.1%)
Unknown2 (22.2%)
User Interaction
None5 (55.6%)
Unknown2 (22.2%)
Required2 (22.2%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None1 (11.1%)
Unknown2 (22.2%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.
Nov 24, 20157.235NOYES
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a St
Apr 10, 20219.031NONO
An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam an
Jul 5, 20207.825NONO
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTH
Oct 4, 20197.825NONO
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and
Aug 21, 20197.824NONO
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and
Aug 21, 20197.023NONO
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUT
Aug 7, 20196.622NONO
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites
May 20, 20195.421NONO
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadcast packet.
May 20, 20155.017NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Steam Client

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.10.91.9127.50.8%01
152882918115.40.9%00