CVE-2019-15511
Summary
| CVE | CVE-2019-15511 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-21 18:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #CQLabs - CVE-2019-15511: Broken Access Control in GOG Galaxy | CQURE Academy | MISC | cqureacademy.com | Third Party Advisory, Vendor Advisory |
| GOG GALAXY 2.0 updates and known issues – GOG.COM SUPPORT CENTER | MISC | support.gog.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.