Vulnerabilities > GOG > Galaxy > 2.0.14

DATE CVE VULNERABILITY TITLE RISK
2020-08-21 CVE-2020-24574 Use of Hard-coded Credentials vulnerability in GOG Galaxy
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands.
local
gog CWE-798
6.9