Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-7352 PoC — GOG Galaxy GalaxyClientService Privilege Escalation

Source
Associated Vulnerability
Title:GOG Galaxy GalaxyClientService Privilege Escalation (CVE-2020-7352)
Description:The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permissions can effectively send any operating system command to the service for execution in this elevated context. The service listens for such commands on a locally-bound network port, localhost:9978. A Metasploit module has been published which exploits this vulnerability. This issue affects the 2.0.x branch of the software (2.0.12 and earlier) as well as the 1.2.x branch (1.2.64 and earlier). A fix was issued for the 2.0.x branch of the affected software.
Description
Powershell implemetation of CVE-2020-7352
Readme
# PS-CVE-2020-7352
Powershell implemetation of CVE-2020-7352
File Snapshot

[4.0K] /data/pocs/9bf76a572efd6bbde6df3a61ef01fc4317eb5f83 ├── [6.2K] CVE-2020-7352.ps1 └── [ 61] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →