Back to Database
Status published
High
CVE-2020-15528
An issue was discovered in GOG Galaxy Client 2.0.17. Local...
Vulnerability Description
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity checks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-15528
Credits & Attribution
No credits recorded in the NVD database.
More from gog
View All →CVE-2022-31262
An exploitable local privilege escalation vulnerability exists in GOG Galaxy...
High
7.8
CVE-2021-26807
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll...
High
7.8
CVE-2020-24574
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as...
High
7.8
CVE-2020-15529
An issue was discovered in GOG Galaxy Client 2.0.17. Local...
High
7.8
CVE-2020-11827
In GOG Galaxy 1.2.67, there is a service that is...
High
7.8
Affected Vendor
Affected Software
galaxy
Vulnerable Versions:
2.0.17
Timeline
Official Publish:
July 5th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.