Galaxy
Vendor:
First CVE: Apr 1, 2019 · Active for 7 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Galaxy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2019
7 years ago
Most Recent CVE
Aug 17, 2022
1,440 days ago
CVE Severity & Scoring
Galaxy15 CVEs
20%
80%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local15 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low11 (73.3%)
High0 (0.0%)
None4 (26.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7352HIGH The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, a | Aug 6, 2020 | 8.8 | 32 | NO | YES |
CVE-2020-24574HIGH The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by i | Aug 21, 2020 | 7.8 | 26 | NO | NO |
CVE-2019-15511HIGH An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthentica | Nov 21, 2019 | 7.8 | 25 | NO | NO |
CVE-2020-11827HIGH In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyCl | Jul 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2018-4048HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker | May 30, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-4049HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An att | Apr 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-3974HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overwrite an executable that is laun | Apr 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-4050HIGH An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder | Apr 1, 2019 | 7.8 | 24 | NO | NO |
CVE-2021-26807HIGH GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally | Apr 30, 2021 | 7.8 | 23 | NO | NO |
CVE-2022-31262HIGH An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder | Aug 17, 2022 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Galaxy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.28.9 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.0.17 | 2 | 7.8 | 1.2% | 0 | 0 |
| 1.2.48.36 | 2 | 7.8 | 0.5% | 0 | 0 |
| 1.2.47 | 4 | 6.1 | 0.3% | 0 | 0 |
| 1.2.45.61 | 1 | 7.8 | 0.5% | 0 | 0 |