PT-2020-19567 · Gog · Gog Galaxy
Jtesta
·
Published
2020-08-06
·
Updated
2022-08-05
·
CVE-2020-7352
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GOG Galaxy versions 1.2.x through 1.2.64
GOG Galaxy versions 2.0.x through 2.0.12
Description
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with an embedded, static RSA private key, an attacker with this key material and local user permissions can send any operating system command to the service for execution in this elevated context. The service listens for such commands on a locally-bound network port,
localhost:9978.Recommendations
For GOG Galaxy versions 1.2.x through 1.2.64, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For GOG Galaxy versions 2.0.x through 2.0.12, update to a version that includes the fix issued for the 2.0.x branch.
Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gog Galaxy