Posted December 15, 2021
Forum: Are you aware of this public known security issue?
From nvd.nist.gov/vuln/detail/CVE-2020-24574
Current Description
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism.
The Proof of Concept github in case someone want to replicate the issue (and/or play the hacker in RL...)
github.com/jtesta/gog_galaxy_client_service_poc
I just realized this problem thanks to reaver894
posting a link to
youtube.com/watch?v=wNYnAgNACnk
--Your thoughts?--
Mine about opening a support ticket asking for answers: I will NOT because,
-My personal experience with GOG tickets is they never attend them (never answer at all and close them without any shame)
-I do not use GOG Galaxy
But, If there is a goodwill pilgrim with better luck/relation with support disposed to take it for the team, thanks in advance!
From nvd.nist.gov/vuln/detail/CVE-2020-24574
Current Description
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe, defeating the TCP-based "trusted client" protection mechanism.
The Proof of Concept github in case someone want to replicate the issue (and/or play the hacker in RL...)
github.com/jtesta/gog_galaxy_client_service_poc
I just realized this problem thanks to reaver894
posting a link to
youtube.com/watch?v=wNYnAgNACnk
--Your thoughts?--
Mine about opening a support ticket asking for answers: I will NOT because,
-My personal experience with GOG tickets is they never attend them (never answer at all and close them without any shame)
-I do not use GOG Galaxy
But, If there is a goodwill pilgrim with better luck/relation with support disposed to take it for the team, thanks in advance!