CVE-2023-50914

MEDIUM

GOG Galaxy (Beta) 2.0.67.2-2.0.71.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary system directories to include Everyone full control permissions by modifying the FixDirectoryPrivileges instruction parameters sent from GalaxyClient.exe to GalaxyClientService.exe.

Scores

CVSS v3 6.7
EPSS 0.0008
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-279
Status published
Published Apr 30, 2024
Tracked Since Feb 18, 2026