CVE-2019-15511

HIGH

GOG Galaxy < 1.2.60 - Missing Authentication

Title source: rule
STIX 2.1

Description

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

Exploits (1)

nomisec WORKING POC 2 stars
by adenkiewicz · poc
https://github.com/adenkiewicz/CVE-2019-15511

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0053
EPSS Percentile 67.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
gog/galaxy < 1.2.60
Published Nov 21, 2019
Tracked Since Feb 18, 2026