
Privilege Escalation Vulnerability in Steam Client Service via IPC Manipulation
A privilege escalation vulnerability in the Steam client service is explained, involving an IPC (Inter-Process Communication) connection that allows an attacker to add their own script to an allow list from a genuine Valve-signed VDF (Valve Data Format) file. The exploit works by manipulating the installation directory or install root parameter, enabling an attacker to specify their own launcher executable as part of a proof of concept payload. Once configured through the IPC connection, this attacker-controlled executable would be executed with system-level privileges. The critical component of this vulnerability is the IPC interaction with the Steam client service, which enables the privilege escalation from a standard user to system-level access.