PT-2020-15748 · Gog · Gog Galaxy
Jtesta
·
Published
2020-08-21
·
Updated
2022-04-29
·
CVE-2020-24574
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GOG GALAXY versions through 2.0.41
Description
The issue allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because an attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism.
Recommendations
For versions through 2.0.41, update to a version later than 2.0.41 to resolve the issue. As a temporary workaround, consider restricting access to the GalaxyClientService.exe to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gog Galaxy