Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4557
https://0xem.ma/cve/2020/04/28/Source-hl2-relaunch-exec.html