CVE-2023-50915 Information
May 04, 2024
cve
Description
An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via a combination of an NTFS Junction and an RPC Object Manager symbolic link and could result in a denial of service.
Reference
https://support.gog.com/hc/en-us/categories/201553005-Downloads-Installing?product=gog https://github.com/anvilsecure/gog-galaxy-app-research https://github.com/anvilsecure/gog-galaxy-app-research/blob/main/advisories/CVE-2023-50915%20-%20DoS.md
Share on: