CVE-2018-4049

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/04/2019
Last modified:
07/06/2022

Description

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gog:galaxy:1.2.48.36:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools