← Back

Your Steam client is a backdoor to Windows SYSTEM—thanks, Valve!

Original version ·

The gaming giant Valve is currently ghosting security researchers, and now the internet has a shiny new toy. A zero-day exploit called BrokenPipe lets any local user hijack your entire Windows PC, and the company just doesn't seem to care.

Researcher Jaydeep Modhwadia, known online as KillaBoi, decided that if Valve wouldn't fix their mess, the whole world should see it. The BrokenPipe vulnerability targets the steamservice.exe background process, which runs with full SYSTEM privileges by default.

The exploit works by tricking the Steam service into trusting a malicious installation script. Because the service fails to verify the actual installation directory, it accepts a legitimate Valve-signed VDF file but processes it in a folder controlled by the attacker.

By invoking specific internal functions like AddInstallScriptToWhiteList and RunInstallScript, the exploit forces steamservice.exe to execute a command prompt as SYSTEM. This turns a simple gaming launcher into a literal skeleton key for your operating system.

This isn't about hacking the signature itself; it's about exploiting a massive logical gap in what that signature actually covers. The PoC was tested on Windows 10 and 11, and since it requires zero user authentication, it’s a dream come true for any malware looking to climb the permission ladder.

It is truly remarkable how a company worth billions can leave a gaping hole in its software for over a year while marking bug reports as duplicates. The situation perfectly highlights the corporate arrogance of treating security researchers like spam rather than free consultants. One has to wonder how many other "ignored" vulnerabilities are currently turning millions of gaming PCs into silent, compromised nodes.

Source: GitHub

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

5/24
  1. Quantum Backend
    valve is a joke. how are we still trusting them with our kernel level access while they can't even patch a basic logic flaw for a year? absolute clowns.
    +5 solidA scathing critique that hits the nail on the head, even if the nail is currently being driven by a kernel-level driver