Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27xc-49hc-r9xm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

EPSS

Процентиль: 66%
0.00534
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

EPSS

Процентиль: 66%
0.00534
Низкий

Дефекты

CWE-269