Galaxy

Vendor:

First CVE: Apr 1, 2019 · Active for 7 years

15
Total CVEs
More Total CVEs than 92% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Galaxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2019
7 years ago
Most Recent CVE
Aug 17, 2022
1,440 days ago

CVE Severity & Scoring

Galaxy15 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local15 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low11 (73.3%)
High0 (0.0%)
None4 (26.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, a
Aug 6, 20208.832NOYES
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by i
Aug 21, 20207.826NONO
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthentica
Nov 21, 20197.825NONO
In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyCl
Jul 14, 20207.824NONO
An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker
May 30, 20197.824NONO
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An att
Apr 2, 20197.824NONO
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overwrite an executable that is laun
Apr 2, 20197.824NONO
An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder
Apr 1, 20197.824NONO
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally
Apr 30, 20217.823NONO
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder
Aug 17, 20227.820NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Galaxy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.28.917.80.5%00
2.0.1727.81.2%00
1.2.48.3627.80.5%00
1.2.4746.10.3%00
1.2.45.6117.80.5%00