Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwfm-4frv-j42h

Опубликовано: 18 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.

EPSS

Процентиль: 76%
0.00983
Низкий

7.8 High

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.

EPSS

Процентиль: 76%
0.00983
Низкий

7.8 High

CVSS3

Дефекты

CWE-281