Severe local 0-Day escalation exploit found in Steam Client Services

Peter Reutemann <[email protected]> Fri, 9 Aug 2019 18:50:51 +1200
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Jfbzzhw7cyyLSZF4_791jhF1_0LfPuwtbr2MwTuVbpHw@mail.gmail.com>
'Earlier today, disgruntled security researcher Vasily Kravets
released a zero-day vulnerability in the Windows version of the
ubiquitous gaming service Steam. The vulnerability allows any user to
run arbitrary code with LOCALSYSTEM privileges using just a very few
simple commands.

The vulnerability lies within Steam Client Service. The service may be
started or stopped by unprivileged users. This becomes a problem
because, when run,Steam Client Service automatically sets permissions
on a range of registry keys. If a mischievous—or outright
malicious—user were to symlink one of these keys to that belonging to
another service, it becomes possible for arbitrary users to start or
stop that service as well. This becomes even more problematic when you
realize that it's possible to pass arguments to services that run
under extremely privileged accounts—such as msiserver, the Windows
Installer service.'

-- source: https://arstechnica.com/gaming/2019/08/severe-local-0-day-escalation-exploit-found-in-steam-client-services/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.