PatchSiren cyber security CVE debrief
CVE-2016-5237 Valvesoftware CVE debrief
CVE-2016-5237 describes weak permissions in the Steam program directory that let local users modify files and potentially gain privileges, including a Trojan-horse replacement of Steam.exe. The CVE was published on 2017-01-23 and NVD later modified the record on 2026-05-13. NVD rates the issue CVSS 4.8 (Medium).
- Vendor
- Valvesoftware
- Product
- Unknown
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for systems running Valve Steam or SteamOS 3.42.16.13, especially endpoints where non-admin local users may be able to reach the Steam installation directory.
Technical summary
NVD classifies the issue as CWE-264 and lists a CVSS v3.0 vector of AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L. The core problem is overly permissive file access in the Steam program directory, which allows a local user to alter program files and potentially influence privilege-sensitive execution. NVD’s vulnerable CPE scope points to SteamOS through version 3.42.16.13, and the record includes third-party references describing the local privilege-escalation impact.
Defensive priority
Medium. The attack requires local access and user interaction, but the impact can include privilege escalation through tampering with installed program files.
Recommended defensive actions
- Audit the Steam program directory permissions and confirm that unprivileged local users cannot write to application binaries or supporting files.
- Remove any unnecessary write access from shared or low-privilege accounts and verify directory ACLs after software installation or updates.
- Apply vendor updates or configuration changes that correct the permission model if they are available for the affected deployment.
- Monitor for unexpected changes to Steam.exe and related files, and use application integrity controls or EDR to detect local tampering.
Evidence notes
All core facts in this debrief come from the supplied CVE description and the NVD record: weak permissions in the Steam program directory, possible privilege gain via file modification, CVSS 4.8/Medium, CWE-264, and the vulnerable CPE entry ending at SteamOS 3.42.16.13. The supplied NVD metadata also lists third-party references from Packet Storm and Exploit-DB; those are noted only as corroborating references, not as sources for exploit detail.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-5237 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-5237
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-5237 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5237
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://packetstormsecurity.com/files/137343/Valve-Steam-3.42.16.13-Local-Privilege-Escalation.html
[email protected] - Exploit, Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/39888/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.