github.com
https://github.com/anvilsecure/gog-galaxy-app-research CVE-2023-50914
MEDIUM
Record summary
CVE-2023-50914 has a selected CVSS score of 6.7 (medium).
Description
A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary system directories to include Everyone full control permissions by modifying the FixDirectoryPrivileges instruction parameters sent from GalaxyClient.exe to GalaxyClientService.exe.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
galaxyBrowse gog / galaxyDefault status: unknown | CVE List | 2.0.67.2 to ≤ v2.071.2 | affected |
References
5github.com
https://github.com/anvilsecure/gog-galaxy-app-research/blob/main/advisories/CVE-2023-50914%20-%20LPE.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-50914 support.gog.com
https://support.gog.com/hc/en-us/categories/201553005-Downloads-Installing?product=gog positronsecurity.com
https://www.positronsecurity.com/blog/2020-08-13-gog-galaxy_client-local-privilege-escalation_deuce