Security Advisory

CVE-2018-3974

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-04-02 15:19:37
Last updated 2024-08-05 04:57:24
Assigner talos
State PUBLISHED

Description

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxys install directory. An attacker can overwrite an executable that is launched as a system service on boot by default to exploit this vulnerability and execute arbitrary code with system privileges.