Skip to main content

Steam vulnerability on Windows lets any normal user silently escalate to SYSTEM

0
Medium
Published: 09/15/2026 (09/15/2026, 00:42:18 UTC)
Source: Reddit Cybersecurity

Description

A local privilege escalation vulnerability in the Steam Client Service on Windows 10 and 11 allows any standard user to silently escalate privileges to SYSTEM without requiring admin rights, UAC prompts, or launching a game. The issue stems from a signature verification gap in Steam's installation process, enabling execution of code as SYSTEM without signature forgery. This was tested on Steam version 10.96.30.42. Valve was notified months prior to public disclosure.

Reddit Discussion

r/cybersecurity·posted by u/xBeT3rDx
00

A newly disclosed local privilege escalation (LPE) in the Steam Client Service affects Windows 10 and 11. Any standard, unprivileged user can get a SYSTEM-level shell — no admin rights, no UAC prompt, no game launch required.

The root cause is a signature coverage gap in Steam's installation verification. The exploit passes a caller-controlled path that Valve's signed VDF never actually covers, letting you run code as SYSTEM without touching or forging the signature at all.

Tested on Steam version 10.96.30.42.

Tagging this as educational/defensive research, but worth mentioning that Valve were notified about this months ago.

Source: https://x.com/bet3rd/status/2099621646155821497

Affected software

Affected versions
=10.96.30.42

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 00:46:31 UTC

Technical Analysis

This vulnerability in the Steam Client Service on Windows arises from a signature coverage gap in Steam's installation verification. An unprivileged user can supply a caller-controlled path that is not covered by Valve's signed VDF, allowing execution of arbitrary code with SYSTEM privileges. The exploit requires no administrative rights or user prompts and does not involve tampering with the signature itself. The flaw was confirmed on Steam version 10.96.30.42 and affects Windows 10 and 11 systems.

Potential Impact

Any standard user on a Windows 10 or 11 system running the affected Steam Client version can escalate privileges to SYSTEM silently. This grants full control over the system, potentially allowing unauthorized actions at the highest privilege level without user consent or awareness.

Mitigation Recommendations

No official patch or remediation information is provided in the available data. Patch status is not yet confirmed — check Valve's official advisory or Steam updates for current remediation guidance. Until a fix is available, restrict unprivileged user access to affected systems or consider disabling the Steam Client Service if feasible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:vulnerability","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["vulnerability"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa8956355bf5e2cf5e42d09

Added to database: 09/15/2026, 00:46:27 UTC

Last enriched: 09/15/2026, 00:46:31 UTC

Last updated: 09/15/2026, 04:31:22 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses