CVE-2020-7352

Public Exploit
GOG Galaxy GalaxyClientService Privilege Escalation

Description

The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permissions can effectively send any operating system command to the service for execution in this elevated context. The service listens for such commands on a locally-bound network port, localhost:9978. A Metasploit module has been published which exploits this vulnerability. This issue affects the 2.0.x branch of the software (2.0.12 and earlier) as well as the 1.2.x branch (1.2.64 and earlier). A fix was issued for the 2.0.x branch of the affected software.

Remediation

Solution:

  • This issue was resolved in version 2.0.13 of the affected software.

Categories

8.4
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 11.58% Top 10%
Third-Party Advisory github.com Third-Party Advisory positronsecurity.com
Affected: GOG GOG GalaxyClientService
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2020-7352?
CVE-2020-7352 has been scored as a high severity vulnerability.
How to fix CVE-2020-7352?
To fix CVE-2020-7352: This issue was resolved in version 2.0.13 of the affected software.
Is CVE-2020-7352 being actively exploited in the wild?
It is possible that CVE-2020-7352 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~12% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2020-7352?
CVE-2020-7352 affects GOG GOG GalaxyClientService.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.