CVE-2020-24574

The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gog:galaxy:*:*:*:*:*:windows:*:*

History

29 Apr 2022, 15:04

Type Values Removed Values Added
References (MISC) https://github.com/jtesta/gog_galaxy_client_service_poc/issues/1#issuecomment-926932218 - (MISC) https://github.com/jtesta/gog_galaxy_client_service_poc/issues/1#issuecomment-926932218 - Issue Tracking, Third Party Advisory

27 Sep 2021, 21:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/jtesta/gog_galaxy_client_service_poc/issues/1#issuecomment-926932218 -
Summary The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.20 allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism. The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism.
CWE CWE-269 CWE-798

Information

Published : 2020-08-21 04:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-24574

Mitre link : CVE-2020-24574

CVE.ORG link : CVE-2020-24574


JSON object : View

Products Affected

gog

  • galaxy
CWE
CWE-798

Use of Hard-coded Credentials