A newly disclosed Windows zero-day vulnerability affects the Steam Client Service, potentially allowing a standard local user to gain NT AUTHORITY\SYSTEM privileges without requiring administrator credentials, a UAC prompt, Steam authentication, or launching a game This article explores privilege escalation steamservice. . Researcher KillaBoi has published a proof of concept, demonstrating local privilege escalation through steamservice.exe, Steam’s privileged Windows service.
According to the technical description, Steam’s service accepts a caller-controlled installation root alongside a genuine Valve-signed install-script VDF, but that path is not protected by the signature. This allows the unprivileged process to influence where the trusted installation workflow finds a launcher, turning a legitimate signed manifest into a vehicle for privileged code execution.
BrokenPipe is therefore not remote compromise by itself, but it could become a powerful second-stage capability after phishing, malware execution, or exploitation of another vulnerability. No public Valve advisory, CVE assignment, or confirmed security update addressing BrokenPipe was identified at the time of publication, maintaining the zero-day status based on the researcher's disclosure and the apparent absence of a vendor fix. Defenders should inventory Steam installations, remove the client where unnecessary, monitor unusual children of steamservice.exe, and alert when executables run as SYSTEM from user-writable directories.
Integrate TI Lookup into your SOC for instant IOC context, ensuring immediate response to threats: Cut your SOC's investigation time significantly.











