PT-2024-14006 · Gog · Gog Galaxy

Jtesta

·

Published

2024-04-08

·

Updated

2024-08-01

·

CVE-2023-50914

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions GOG Galaxy (Beta) versions 2.0.67.2 through 2.0.71.2
Description A Privilege Escalation issue in the inter-process communication procedure allows authenticated users to change the DACL of arbitrary system directories to include Everyone full control permissions by modifying the FixDirectoryPrivileges instruction parameters sent from GalaxyClient.exe to GalaxyClientService.exe.
Recommendations For GOG Galaxy (Beta) versions 2.0.67.2 through 2.0.71.2, consider disabling the FixDirectoryPrivileges instruction until a patch is available to prevent exploitation. Restrict access to the GalaxyClientService.exe to minimize the risk of exploitation. Avoid using the FixDirectoryPrivileges parameter in the affected inter-process communication procedure until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2023-50914

Affected Products

Gog Galaxy