ZeroHour

CVE-2018-4050

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
Description

An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder permissions leading to execution of arbitrary code with elevated privileges.

Vendors
gog
Products
galaxy
Weakness
CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news