Steam client flaw with no fix enables privilege elevation on Windows
Brief
A proof-of-concept exploit named BrokenPipe abuses the Steam Client Service to elevate a standard Windows user to NT AUTHORITY\SYSTEM without displaying a UAC prompt or requiring administrator credentials. The issue was disclosed on GitHub by security researcher KillaBoi (@killa), who says Valve had been notified about the vulnerability since March. According to the researcher, the …
The post Steam client flaw with no fix enables privilege elevation on Windows appeared first on CyberInsider .
