Security Advisory

CVE-2020-15529

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-07-05 00:31:38
Last updated 2024-08-04 13:15:20
Assigner mitre
State PUBLISHED

Description

An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and can be exploited by using opportunistic locks.