GOG
GOG Galaxy: vulnerabilidades y CVE
GOG Galaxy tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50915 | Media (6.5) | 0.68% | — | 30 abr 2024 | An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via a combination of an NTFS Junction and an… |
| CVE-2023-50914 | Media (6.7) | 0.70% | — | 30 abr 2024 | A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary system directories to include… |
| CVE-2022-31262 | Alta (7.8) | 0.51% | — | 17 ago 2022 | An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the… |
| CVE-2021-26807 | Alta (7.8) | 0.48% | — | 30 abr 2021 | GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading. |
| CVE-2020-24574 | Alta (7.8) | 0.62% | — | 21 ago 2020 | The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to… |
| CVE-2020-7352 | Alta (8.8) | 3.8% | — | 6 ago 2020 | The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and… |
| CVE-2020-11827 | Alta (7.8) | 0.34% | — | 14 jul 2020 | In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyClientService.exe. After that, the… |
| CVE-2020-15529 | Alta (7.8) | 1.0% | — | 5 jul 2020 | An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and… |
| CVE-2020-15528 | Alta (7.8) | 1.3% | — | 5 jul 2020 | An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity checks. |
| CVE-2019-15511 | Alta (7.8) | 0.75% | — | 21 nov 2019 | An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to… |
| CVE-2018-4048 | Alta (7.8) | 0.60% | — | 30 may 2019 | An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of the… |
| CVE-2018-4053 | Media (5.5) | 0.33% | — | 2 abr 2019 | An exploitable local denial-of-service vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can send malicious data to the root-listening service, causing the… |
| CVE-2018-4052 | Media (5.5) | 0.36% | — | 2 abr 2019 | An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can pass a PID and receive information running on it that would… |
| CVE-2018-4051 | Media (5.5) | 0.28% | — | 2 abr 2019 | An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally create directories and subdirectories on the root… |
| CVE-2018-4049 | Alta (7.8) | 0.32% | — | 2 abr 2019 | An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of… |
| CVE-2018-3974 | Alta (7.8) | 0.53% | — | 2 abr 2019 | An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overwrite an executable that is launched as a system service on boot by… |
| CVE-2018-4050 | Alta (7.8) | 0.35% | — | 1 abr 2019 | An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder permissions leading to execution of… |