Top 5 This Week

Related Posts

Steam ‘BrokenPipe’ Security Flaw Unfixed Months After Researcher Reported It

  • BrokenPipe can elevate a standard Windows user to NT AUTHORITYSYSTEM, without requiring an administrator password or triggering a UAC prompt.
  • The researcher says Valve was notified through HackerOne in March 2026, but the report was closed as a duplicate before proof-of-concept code became public in September.
  • BrokenPipe is not remotely exploitable by itself: an attacker already needs the ability to execute code locally, but existing malware could potentially use the flaw to gain far more powerful access.

A publicly disclosed vulnerability in Steam’s Windows service can elevate an ordinary user process to NT AUTHORITY\SYSTEM without an administrator password or UAC prompt. The researcher behind BrokenPipe says Valve was notified in March, months before working proof-of-concept code became public.

A Windows PC does not necessarily become compromised simply because Steam is installed on it. But if malware has already found its way onto the machine, a publicly available Steam exploit could potentially give it something considerably more dangerous: SYSTEM privileges.

The vulnerability, named BrokenPipe by the security researcher who disclosed it, affects the Steam Client Service running on Windows. It is a local privilege-escalation flaw capable of turning code running under a standard Windows account into a process operating as NT AUTHORITY\SYSTEM, one of the most powerful security contexts available on Windows.

- Advertisement -

According to the researcher’s disclosure, exploiting BrokenPipe does not require an administrator password and does not trigger the familiar Windows User Account Control prompt asking the user to approve elevated privileges. That combination makes the vulnerability particularly interesting from a gaming-security perspective. Steam is installed on an enormous number of Windows gaming PCs, and privilege-escalation vulnerabilities can provide attackers with a second stage after malicious software has already gained an initial foothold.

What is the Steam BrokenPipe vulnerability?

BrokenPipe targets the Steam Client Service, a Windows service used by Valve’s desktop client to perform operations that require elevated privileges. The service operates with SYSTEM-level permissions while communicating with ordinary user processes. That relationship is important because Windows deliberately separates what a standard account can do from actions requiring administrator or SYSTEM privileges. BrokenPipe exploits that boundary.

The researcher, who publishes under the name KillaBoi, demonstrated a method through which a standard local user can abuse communication with the Steam service and ultimately execute code with SYSTEM privileges. The published research reports successful testing against Steam client version 10.96.30.42 on 64-bit versions of both Windows 10 and Windows 11.

BrokenPipe does not let someone remotely hack your PC

There is an important limitation that should not disappear beneath the severity of SYSTEM access, BrokenPipe is a local privilege-escalation vulnerability, not a remote-code-execution exploit.

An attacker cannot simply find a Steam user online and use BrokenPipe to take control of that person’s computer. Steam must be installed, the relevant service must be available, and the attacker must already have the ability to execute code on the Windows machine as a standard user. That distinction substantially changes the threat model, but it does not make the vulnerability harmless.

Privilege escalation is frequently valuable after an attacker has already gained limited access to a system. Malware initially running with ordinary user permissions faces restrictions on what it can access or modify. Elevating that process to SYSTEM can remove many of those barriers. In practical terms, BrokenPipe is not necessarily the way an attacker gets through the front door. It can become useful after something malicious is already inside.

Why SYSTEM access matters

NT AUTHORITY\SYSTEM sits above an ordinary Windows user and carries extensive privileges intended for the operating system and trusted services. If malware successfully escalates into that context, it can potentially access resources unavailable to the compromised user account, interfere with system-level components and operate with considerably fewer restrictions. This is why local privilege-escalation vulnerabilities are commonly paired with other attacks. An information stealer, remote-access trojan or malicious executable might initially arrive through an unrelated route but subsequently exploit a local vulnerability to strengthen its position on the machine.

Gaming PCs provide an especially relevant environment for that threat model. Players routinely download mods, community tools, overlays and other third-party software, while cracks, cheats and fake game downloads remain obvious routes through which malicious executables can reach a system.

The technical vulnerability is only half of the BrokenPipe story. The disclosure timeline raises another question: how long Valve has known about it. KillaBoi says the vulnerability was reported to Valve through its HackerOne bug-bounty program in March 2026. According to the researcher, the submission was subsequently closed as a duplicate.

In vulnerability-reporting programs, a duplicate classification generally means the underlying issue has already been reported by another researcher. It does not, by itself, establish whether the vulnerability has been fixed or when the original report was received. Months later, however, BrokenPipe became public. Working proof-of-concept material was published in mid-September, allowing other researchers to examine and reproduce the technique rather than relying solely on a private vulnerability report.

There is still no publicly confirmed BrokenPipe fix

That brings the timeline to its most consequential point. Reports published after the September disclosure found no corresponding Valve security advisory or CVE identifying a BrokenPipe fix. Cybersecurity News and CyberInsider both reported on the vulnerability following publication of the proof of concept, while later reporting continued to describe the issue as unpatched.

As of October 4, TalkEsport could not identify a Valve security advisory, CVE entry or Steam client release note explicitly confirming that BrokenPipe has been fixed. That wording is important. The absence of a publicly identified patch is not proof that Valve has done nothing internally, nor does it establish that every current Steam installation remains exploitable. Without a Valve advisory or independent testing of the latest client, TalkEsport cannot make either claim.

What can be established publicly is that the researcher says Valve received the vulnerability in March, working exploit code is now available, and there is no publicly documented fix that TalkEsport could identify six months after that reported disclosure.

Valve has faced a remarkably similar situation before

BrokenPipe is particularly notable because this is not Valve’s first dispute involving privilege escalation in the Steam Client Service. In 2019, security researcher Vasily Kravets reported vulnerabilities involving Steam and Windows privilege escalation through Valve’s HackerOne program. One of his reports was rejected as outside the scope of Valve’s bounty program, leading Kravets to disclose the issue publicly.

Valve subsequently acknowledged that the decision had been wrong.

“His report was classified as out of scope. This was a mistake.”

Valve, 2019

The company patched the vulnerabilities and changed its bug-bounty rules to explicitly accept local privilege-escalation reports. Seven years later, BrokenPipe places another reported Steam privilege-escalation vulnerability under scrutiny, although the circumstances surrounding the two disclosures are not identical.

The local-access requirement also means BrokenPipe does not present the same level of risk to every Steam user. A privately owned gaming PC with a single trusted user presents a different environment from a machine shared among several Windows accounts. Gaming cafés and LAN centres, university or school computers, shared family PCs and other multi-user systems create more opportunities for an unprivileged account to exist alongside software and data belonging to other users.

On those machines, the security boundary between a standard account and SYSTEM is particularly important. A local privilege-escalation vulnerability potentially undermines the very separation administrators rely upon when giving users restricted accounts.

What Steam users can do while BrokenPipe remains unresolved

There is no reason for ordinary Steam users to panic or assume their machines have been compromised. BrokenPipe cannot remotely infect a computer by itself, and exploiting it requires code to already be running locally. That makes preventing the initial compromise the most useful defence. Players should be particularly cautious with cracked games, cheats, unofficial executables, suspicious mods and fake downloads. Software promising free games, skins or cheating functionality remains a natural delivery mechanism for malware precisely because users voluntarily execute it.

Keeping Steam and Windows updated remains sensible as well, although users should not interpret an ordinary Steam update as confirmation that BrokenPipe has been patched unless Valve or independent security research establishes that fact. Administrators responsible for shared gaming machines face a different calculation. Systems that do not require Steam can have the client removed, while environments that depend on it warrant closer monitoring until the vulnerability’s status becomes clearer.

Vulnerabilities exist privately for months or even years without presenting an immediate practical threat to ordinary users. Public disclosure changes that equation because technical details no longer remain confined to the original researcher and vendor. BrokenPipe has crossed that threshold. The vulnerability has been publicly documented and proof-of-concept material exists. At the same time, TalkEsport could not find a Valve advisory identifying a corresponding fix as of October 4. That does not mean someone can remotely compromise millions of Steam accounts, nor does it mean every Windows PC running Steam is currently vulnerable. It does mean that a publicly documented path from standard-user execution to SYSTEM privileges deserves a clear answer about its remediation status.

For Steam’s enormous Windows user base, the most useful development now would therefore be a straightforward one: confirmation from Valve about whether BrokenPipe affects the current Steam client and, if it does, when users can expect it to be fixed.

- Advertisement -
Ritambhara Tripathi
Ritambhara Tripathi
Ritambhara has acquired masters degree in Law from Jodhpur University. She was awarded LLM almost a decade ago, after which she continued to practice law at various firms in the domain of corporate law.

Popular Articles