PT-2024-14007 · Gog · Gog Galaxy

Published

2024-04-08

·

Updated

2024-07-03

·

CVE-2023-50915

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GOG Galaxy (Beta) versions 2.0.67.2 through 2.0.71.2
Description An issue exists in GalaxyClientService.exe that could allow authenticated users to overwrite and corrupt critical system files via a combination of an NTFS Junction and an RPC Object Manager symbolic link, resulting in a denial of service.
Recommendations For versions 2.0.67.2 through 2.0.71.2, consider disabling the GalaxyClientService.exe until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2023-50915

Affected Products

Gog Galaxy