← Back to CVE List

CVE-2022-31262

Published: 2022-08-17T15:15Z
Last Modified: 2024-11-21T07:04Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt