
Proof-of-concept for CVE-2020-25769, a local privilege escalation vulnerability in GOG Galaxy 2.0's GalaxyClientService component on Windows.
GOG Galaxy 2.0 is a platform developed by CD Project designed as a storefront, software delivery, social network and as a unified game launcher. Under Windows the client relies on the GalaxyClientService component for handling privileged tasks. The application fails to properly verify the identity of who request a privileged tasks. This situtation maybe abused to obtain a local privilege escalation vulnerability.