CVE-2020-15529: Gog Galaxy

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and can be exploited by using opportunistic locks.

Affected products

  • Gog Galaxy: version 2.0.17 only

Published 2020-07-05. Last modified 2026-06-17.