VYPR
High severity7.8NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026

CVE-2020-11827

CVE-2020-11827

Description

In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyClientService.exe. After that, the attacker can re-start this service as an unprivileged user to escalate his/her privileges and run commands on the machine with SYSTEM rights.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • GOG/Galaxydescription
  • Gog.com/Galaxyllm-create2 versions
    1.2.67+ 1 more
    • (no CPE)range: 1.2.67
    • cpe:2.3:a:gog:galaxy:*:*:*:*:*:*:*:*range: <1.2.67

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.