<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Unpatched Steam Flaw Gives Local Windows Users SYSTEM Access

A public proof-of-concept escalates any standard Steam user to SYSTEM on Windows. Valve was reportedly notified in March 2026 and has not shipped a fix.
Content Team

A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.

Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.

KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.

With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo