Security readout for executives and security teams
Plain-English summary
CVE-2020-24574 is a local privilege escalation in GOG GALAXY on Windows. An already authenticated user can abuse the Galaxy client service to run commands as SYSTEM. This matters on shared workstations, developer machines, kiosks, or unmanaged endpoints where GOG GALAXY is installed. The bundle does not provide a CVSS score.
Executive priority
Treat this as a high-priority endpoint hygiene issue, not an internet-wide emergency. Remove or update affected GOG GALAXY installations on managed systems, with priority for shared Windows hosts and sensitive employee workstations.
Technical view
The issue affects GalaxyClientService.exe in GOG GALAXY through 2.0.41. The CVE description says an attacker can inject a DLL into GalaxyClient.exe, bypass the TCP-based trusted-client check, and instruct the Windows service to execute arbitrary commands as SYSTEM. The source bundle does not identify a CWE, CVSS vector, or definitive fixed version.
Likely exposure
Exposure is limited to Windows systems running GOG GALAXY through 2.0.41, especially where non-administrative authenticated users can log in locally. Enterprise exposure may be low unless gaming software is present on endpoints.
Exploitation context
A public proof-of-concept repository is referenced in the source bundle. However, CISA KEV is false and the provided sources do not state active exploitation in the wild. This is a post-authentication local issue, not a remote unauthenticated compromise.
Researcher notes
Key uncertainty is remediation status: the provided bundle names vulnerable versions through 2.0.41 but does not provide a verified fixed version. Public PoC availability raises practical risk, but validation should avoid reproducing exploitation on production hosts.
Mitigation direction
- Inventory Windows endpoints for GOG GALAXY and GalaxyClientService.exe.
- Remove GOG GALAXY where it is not business-required.
- Check GOG vendor guidance for a fixed or current safe version.
- If vendor guidance confirms a fix, update affected clients.
- Restrict local interactive access on shared or sensitive Windows systems.
Validation and detection
- Confirm whether GalaxyClientService.exe is installed on Windows endpoints.
- Record installed GOG GALAXY versions and compare against 2.0.41.
- Prioritize systems with shared local users or elevated business sensitivity.
- Review endpoint telemetry for unexpected child processes from GalaxyClientService.exe.
- Document any compensating controls if removal or update is delayed.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Privilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2020-24574 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.gog.com/galaxyCVE reference · x_refsource_MISC
- https://www.positronsecurity.com/blog/2020-08-13-gog-galaxy_client-local-privilege-escalation_deuce/CVE reference · x_refsource_MISC
- https://github.com/jtesta/gog_galaxy_client_service_pocCVE reference · x_refsource_MISC
- https://github.com/jtesta/gog_galaxy_client_service_poc/issues/1#issuecomment-926932218CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
