BrokenPipe PoC Exploits Steam Client Service for Silent SYSTEM Privilege Escalation on Windows
A new proof of concept called BrokenPipe shows how a standard user on Windows can elevate privileges to NT AUTHORITY\SYSTEM through the Steam Client Service without an administrator password or any UAC prompt.
The demonstration describes a path that lets any non-administrator user execute code as NT AUTHORITY\SYSTEM. Tests reproduced the behavior on Windows 10 and Windows 11 with Steam 10.96.30.42. The affected component is steamservice.exe, the executable behind the Steam Client Service.
This Windows service runs with maximum privileges and exposes an interface for maintenance and deployment tasks. The design, common in software that needs to update or install dependencies, becomes an attack surface when validation logic fails to close all vectors.
The technical explanation points to insufficient signature validation in VDF installation scripts. The service does not fully control the path it accepts and executes; part of that path remains outside signature coverage, allowing an attacker to dictate where the script is loaded from.
The exploit uses the service interface to add a malicious script to an allowlist and force its execution, resulting in the payload running with SYSTEM privileges. The flaw is not remotely exploitable; the attacker must first execute code locally with a standard account.
This scenario fits shared computers, library workstations, cybercafés, or corporate environments where some users should not be able to elevate privileges. A successful LPE can turn a limited intrusion into full machine control.
No public CVE is associated with the issue, and there is no confirmation of active exploitation in real campaigns. Valve received notification months before public disclosure, with March cited as the notification date.
Administrators should inventory Windows systems running Steam, evaluate whether the Steam Client Service is necessary on sensitive or shared endpoints, and apply compensating controls such as application allowlisting and script execution policies. Monitoring for SYSTEM-context processes tied to steamservice.exe and anomalous launches of cmd.exe from Steam paths is also recommended.
Related articles
Apache HTTP Server 2.4.69 Patches 20 Vulnerabilities Including CVSS 9.8 Issues
The Apache HTTP Server development team released version 2.4.69 on October 1, 2026, addressing a total of 20 vulnerabilities. While the Apache Security Team assessed most issues as moderate or low in impact, several vulnerabilities received CVSS base scores as high as 9.8. The update includes fixes for stack-based buffer overflows, use-after-free conditions, and out-of-bounds writes affecting multiple modules. No vulnerabilities were rated Critical or Important by the developers, with five classified as Moderate and fifteen as Low. Specific fixes cover the mod_vhost_alias, mod_http2, mod_dav, and mod_dav_fs modules, along with Windows-specific path handling problems.
WatchGuard Fireware OS Affected by 15 Vulnerabilities Including Critical CVE-2026-86131
WatchGuard Technologies disclosed 15 vulnerabilities in Fireware OS, the operating system powering its UTM appliances. The advisories were published between September 29 and 30, 2026, covering issues that range from remote code execution and authorization bypass to file disclosure and denial of service. Impact varies by deployment, yet none of the flaws had been observed in active exploitation at disclosure time. The most severe finding, CVE-2026-86131 in BOVPN Over TLS, received a CVSS v4.0 base score of 9.2 and Critical rating. This code-injection flaw in client configuration handling allows an attacker who controls the VPN server to execute arbitrary commands with root privileges on the connecting Firebox device. The remaining vulnerabilities affect multiple components and are tracked under separate CVE identifiers listed in the official advisories.
Rust Researcher Builds AI Pipeline to Test 900 Vulnerability Hypotheses Across Crates and Linux Kernel
Sergey Gordeychik developed the rust-in-peace research harness that combines multiple LLM agents, traditional SAST tools, and dynamic verification to hunt for memory-safety, logic, and API misuse issues in Rust code. The system generates independent hypotheses, attempts to refute them with separate agents, then validates survivors through fuzzing, protocol tests, or container execution. Starting from the Damn Vulnerable Rust Application, the pipeline was expanded to popular crates including x509-parser, h2, and lopdf, ultimately producing a Linux kernel patch. Experiments showed that three parallel analysis passes yielded 20 confirmed findings after triage, with nine appearing in all passes. The work also highlighted how models can produce convincing but false positives when context such as dependency checks or call order is missing. Gordeychik presented the approach at ZeroNights under the title Rust in Peace: How to Raise Your Own Pet Mythos.
Critical Zero-Day Vulnerability in FortiMail Allows Unauthenticated File Writes
Fortinet disclosed a critical zero-day vulnerability in its FortiMail email security product that is already being exploited in attacks. The flaw, tracked as CVE-2026-104286, affects the graphical user interface component and stems from improper sanitization of path traversal and NULL byte sequences. Attackers can craft malicious HTTP requests to write arbitrary files to the system without authentication. The vulnerability received a CVSS v3.1 base score of 9.8, classifying it as Critical. Fortinet discovered the issue internally but has also received reports of active exploitation. Planned patches include FortiMail 8.0.2, 7.6.7, and 7.4.9, while users on the 7.2 branch are advised to migrate to 7.4 or later.