Updated:10:45 AM CEST Sep,18
(new)
(c) 1998-2026 Gameguru Mania
Privacy Policy statement
|
Unpatched Steam Bug Lets a Local Windows User Become SYSTEM - tech|
| (hx) 10:45 AM CEST - Sep,18 2026 | A public proof-of-concept called BrokenPipe shows that a standard Windows user can raise privileges to NT AUTHORITYSYSTEM through Steam’s Client Service.
Researcher KillaBoi published the demonstration on GitHub and said it was tested on Steam 10.96.30.42 on fully updated 64-bit Windows 10 and 11. The service already runs as SYSTEM; the proof of concept makes it launch a program with those rights without an administrator password or a UAC prompt, and a Steam login is not required.
No CVE has been assigned, Valve has not issued a public advisory, and there is no confirmed evidence of attacks in the wild. The researcher claims Valve was told in March 2026 and that a HackerOne report was later marked a duplicate; Cyberinsider said it contacted Valve and received no reply.
Until Valve ships a client fix, this remains a local escalation issue on PCs that already have Steam installed - not a remote hack of Steam accounts.
**Sources**
- https://gbhackers.com/steam-windows-vulnerability/
- https://github.com/KillaBoi/BrokenPipe
- https://cyberinsider.com/steam-client-flaw-with-no-fix-enables-privilege-elevation-on-windows/
- https://habr.com/ru/news/1082774/ |
|
last 10 comments: All comments
|
|