CVE-2020-7352 is a privilege escalation vulnerability in the GOG GalaxyClientService component, affecting versions 2.0.12 and earlier, and 1.2.64 and earlier, where the service runs with SYSTEM privileges. An attacker with local user permissions can exploit a hardcoded RSA private key to send arbitrary operating system commands to the service via localhost:9978, leading to full compromise of the system. This vulnerability has a CVSS score of 8.8 (High) due to its local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not on the KEV catalog or actively exploited in the wild, a Metasploit module exists, indicating readily available exploit code, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.2.0, <= 1.2.64CPE matchmatch criteria | cpe:2.3:a:gog:galaxy:*:*:*:*:*:windows:*:* | ||
>= 2.0.0, <= 2.0.12CPE matchmatch criteria | cpe:2.3:a:gog:galaxy:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.