secure-77/CVE-2022-31262

secure-77/CVE-2022-31262

Releases0
Stars4
GOG Galaxy LPE Exploit

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.