AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-15316

HIGH · CVSS 7 EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-15316
Severity
HIGH
CVSS
7
EPSS
0.39%
Windows

Original NVD Description

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.