CVE-2021-30481
 
Severity Score
9.0
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Valve Steam through 2021-04-10, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.
Valve Steam hasta el 10-04-2021, cuando un juego del motor de Origen es instalado, permite a usuarios autenticados remotos ejecutar código arbitrario debido a un desbordamiento del búfer que ocurre para una invitación de Steam después de un clic
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-04-10 CVE Reserved
- 2021-04-10 CVE Published
- 2021-04-20 First Exploit
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://news.ycombinator.com/item?id=26762170 | Issue Tracking | |
https://twitter.com/floesen_/status/1337107178096881666 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/floesen/CVE-2021-30481 | 2021-04-20 | |
https://github.com/JHVIW/jhviw.github.io | 2024-11-12 | |
https://twitter.com/the_secret_club/status/1380868759129296900 | 2024-08-03 | |
https://www.youtube.com/watch?v=rNQn--9xR1Q | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Valvesoftware Search vendor "Valvesoftware" | Steam Client Search vendor "Valvesoftware" for product "Steam Client" | <= 2021-04-10 Search vendor "Valvesoftware" for product "Steam Client" and version " <= 2021-04-10" | - |
Affected
|