GOG's vulnerability profile centers on its Galaxy client and launcher, a widely deployed platform for game distribution and library management that sits in the trust chain between the vendor and end users. The recurring exposure reflects the sensitive data and privileged execution context of a game launcher: hard-coded credentials, improper permission assignment, and information-disclosure weaknesses that can undermine user authentication and system integrity. Vulnerabilities affecting the vendor have a moderate tendency toward public exploit availability, consistent with the appeal of client-side tooling for security research. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gog over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7352HIGH The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, a | Aug 6, 2020 | 8.8 | 32 | NO | YES |
CVE-2020-24574HIGH The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by i | Aug 21, 2020 | 7.8 | 26 | NO | NO |
CVE-2019-15511HIGH An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthentica | Nov 21, 2019 | 7.8 | 25 | NO | NO |
CVE-2020-11827HIGH In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyCl | Jul 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2018-4048HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker | May 30, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-4049HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An att | Apr 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-3974HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overwrite an executable that is laun | Apr 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-4050HIGH An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder | Apr 1, 2019 | 7.8 | 24 | NO | NO |
CVE-2021-26807HIGH GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally | Apr 30, 2021 | 7.8 | 23 | NO | NO |
CVE-2022-31262HIGH An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder | Aug 17, 2022 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gog.
Media articles that mention a CVE ID that affects a product developed by Gog — matched by CVE ID, not by vendor name.