Vulnerability Management

BrokenPipe exploit grants SYSTEM privileges via Steam client service

(Adobe Stock)

A new proof-of-concept exploit named BrokenPipe has been disclosed, which abuses the Steam Client Service on Windows to elevate a standard user to NT AUTHORITYSYSTEM privileges without triggering a User Account Control (UAC) prompt or requiring administrator credentials. The vulnerability was publicly released by security researcher KillaBoi after Valve was notified in March, with further coverage provided by Cyber Insider.

The BrokenPipe exploit targets steamservice.exe, a Windows service installed with Valve's Steam client that runs with SYSTEM privileges. The vulnerability arises from how the Steam Client Service handles signed installation-script VDF files. While the VDF itself is legitimately signed by Valve, the service allegedly uses a caller-controlled installation root that is not covered by this signature. The exploit connects to the Steam Client Service without administrator rights and uses specific functions to add a malicious installation script to a whitelist and then execute it. This allows the SYSTEM-level Steam service to run an attacker-controlled launcher with its own privileges, ultimately executing commands like cmd.exe as SYSTEM.

Although the exploit requires an attacker to already have local code execution, this flaw could be leveraged by malware to gain full SYSTEM-level control on a compromised machine. Testing was performed on Windows 10 and Windows 11 systems with Steam version 10.96.30.42.

Source: Cyber Insider

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds