A publicly disclosed zero-day in the Windows Steam Client Service (steamservice.exe), dubbed BrokenPipe, can let a standard local user execute attacker-controlled code as NT AUTHORITY\SYSTEM. The flaw reportedly exploits a signature-coverage gap in Steam’s installation-script workflow: the privileged service accepts a legitimate Valve-signed VDF file together with a caller-controlled installation-root path, enabling a malicious launcher placed at that location to run with SYSTEM privileges.
Researcher KillaBoi published a proof of concept reportedly effective against Steam version 10.96.30.42 on 64-bit Windows 10 and Windows 11, and stated Valve had been aware of the issue since March 2026. Exploitation requires prior local code execution and an installed, available Steam service, making it a post-compromise privilege-escalation vector rather than a remote entry point. No public Valve advisory, CVE, or confirmed remediation was available; organizations should review Steam installations and investigate SYSTEM-level child processes launched by steamservice.exe, particularly where executables originate from user-writable paths.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
KillaBoi published a proof of concept for BrokenPipe, which abuses a signature-coverage gap in Steam's installation-script workflow to have steamservice.exe execute an attacker-controlled launcher as NT AUTHORITY\SYSTEM. The reported PoC worked against Steam 10.96.30.42 on recent 64-bit Windows 10 and Windows 11 systems.
Researcher KillaBoi stated that Valve had known about the BrokenPipe local privilege-escalation issue affecting the Windows Steam Client Service since March 2026.
A related HackerOne submission concerning the BrokenPipe issue was reportedly marked as a duplicate.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.