In Valve Steam Client for Windows through 2019-08-07, HKLMSOFTWAREWow6432 NodeValveSteam has explicit “Full control” for the Users group, which allows local users to gain NT AUTHORITYSYSTEM access. The vendor disputes the significance of this finding; the discoverer was reportedly told that the Steam threat model excludes “Attacks that require physical access to the user’s device” The vulnerability has been modified since it was last analyzed by the NVD.”]

