#VU52200 Buffer overflow in Steam - CVE-2021-30481

 

#VU52200 Buffer overflow in Steam - CVE-2021-30481

Published: April 14, 2021 / Updated: May 18, 2021


Vulnerability identifier: #VU52200
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2021-30481
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Steam
Software vendor:
Valve Software

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing Steam invites. A remote attacker can send a specially crafted invite, trigger a buffer overflow after the user clicks on the invite, and execute arbitrary code on the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links