A zero-day vulnerability in the Windows Steam Client Service allows a standard local user to gain NT AUTHORITYSYSTEM privileges without administrator credentials, User Account Control prompts, or Steam authentication. Discovered by researcher KillaBoi, the flaw is due to the way Steam's service accepts a caller-controlled installation root alongside a legitimate Valve-signed install script. This vulnerability enables an unprivileged process to manipulate the installation workflow to execute privileged code. The proof of concept, named BrokenPipe, demonstrates this exploit using a PowerShell script that embeds the signed VDF and establishes inter-process communication with the Steam Client Service. Testing has shown success against Steam version 10.96.30.42 on Windows 10 and 11. Valve has been aware of the issue since March 2026, but no public advisory or security update has been issued. Organizations are advised to inventory Steam installations, remove unnecessary clients, and monitor for unusual processes related to steamservice.exe.