CVE-2020-24574
Summary
| CVE | CVE-2020-24574 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-21 04:15:00 UTC |
| Updated | 2022-04-29 15:04:00 UTC |
| Description | The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Positron Security | MISC | www.positronsecurity.com | Exploit, Third Party Advisory |
| PoC status update · Issue #1 · jtesta/gog_galaxy_client_service_poc · GitHub | MISC | github.com | |
| GitHub - jtesta/gog_galaxy_client_service_poc: Proof-of-concept exploit for GOG Galaxy Client vulnerabilities | MISC | github.com | Exploit, Third Party Advisory |
| Galaxy - GOG.com | MISC | www.gog.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.