An exploitable local privilege escalation vulnerability...
High severity
Unreviewed
Published
Aug 18, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Aug 17, 2022
Published to the GitHub Advisory Database
Aug 18, 2022
Last updated
Jan 29, 2023
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.
References