PT-2020-12875 · Gog · Gog Galaxy
Published
2020-07-14
·
Updated
2021-07-21
·
CVE-2020-11827
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GOG Galaxy version 1.2.67
Description
The issue concerns weak file/service permissions in the GalaxyClientService.exe service. An attacker can exploit this by replacing the legitimate GalaxyClientService.exe with malicious code, potentially allowing them to escalate privileges and execute commands with SYSTEM rights by restarting the service as an unprivileged user.
Recommendations
For GOG Galaxy version 1.2.67, consider restricting access to the GalaxyClientService.exe service to prevent unauthorized restarts and privilege escalation until a patch is available. As a temporary workaround, monitor the service for any suspicious activity and ensure that only authorized users can interact with it.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gog Galaxy