An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-21T17:47:40

Updated: 2024-08-05T00:49:13.601Z

Reserved: 2019-08-23T00:00:00

Link: CVE-2019-15511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-11-21T18:15:11.040

Modified: 2021-07-21T11:39:23.747

Link: CVE-2019-15511

cve-icon Redhat

No data.