It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
like really is Galaxy 2.0 save again to use? it have a serious issue from like 16 months in it already.
Can you be more specific? your post is rather vague so it is really difficult to answer as different people can have different opinions on what the serious issue is, for some people the fact that galaxy exists is a serious issue for example
avatar
wolfsite: Can you be more specific? your post is rather vague so it is really difficult to answer as different people can have different opinions on what the serious issue is, for some people the fact that galaxy exists is a serious issue for example
it's about the "admin" exploit within galaxy 2.0
I read up on it (multiple sources) and the general consensus is that for this Admin exploit to work you computer needs to already be compromised so in this case you have bigger problems that need to be taken care of. GOG is working on a solution but it looks like it requires some deep reworking.

There are claims though that this exploit also exists is Steam and other client programs like Uplay and some state this comes down to how Microsoft has privilege access setup.

If you are concerned about this the best option is not use Galaxy as it is optional and you can easily get your games with the offline installers.

This exploit though requires your PC to already have been attacked or be in a compromised state.
avatar
Abishia: it's about the "admin" exploit within galaxy 2.0
That's not fixed. There are at least two recently active threads about this.
https://www.gog.com/forum/general/gog_galaxy_security_issue_cve202024574/post3
https://www.gog.com/forum/general/0day_found_in_the_galaxy_client_news_is_spreading_on_the_web/post97
avatar
wolfsite: I read up on it (multiple sources) and the general consensus is that for this Admin exploit to work you computer needs to already be compromised so in this case you have bigger problems that need to be taken care of. GOG is working on a solution but it looks like it requires some deep reworking.

There are claims though that this exploit also exists is Steam and other client programs like Uplay and some state this comes down to how Microsoft has privilege access setup.

If you are concerned about this the best option is not use Galaxy as it is optional and you can easily get your games with the offline installers.

This exploit though requires your PC to already have been attacked or be in a compromised state.
from what i can tell (i can be wrong here)
that yea your system most be compromised but your system works on comparments (like buildings that have fire rooms)
Galaxy have Admin rights (even if your system is being comprimised by low level acess for example the standard guest login rights of any windows system)

for Uplay or steam i not hear the same issues exist so i can't really say much about it.
avatar
wolfsite: I read up on it (multiple sources) and the general consensus is that for this Admin exploit to work you computer needs to already be compromised so in this case you have bigger problems that need to be taken care of. GOG is working on a solution but it looks like it requires some deep reworking.

There are claims though that this exploit also exists is Steam and other client programs like Uplay and some state this comes down to how Microsoft has privilege access setup.

If you are concerned about this the best option is not use Galaxy as it is optional and you can easily get your games with the offline installers.

This exploit though requires your PC to already have been attacked or be in a compromised state.
avatar
Abishia: from what i can tell (i can be wrong here)
that yea your system most be compromised but your system works on comparments (like buildings that have fire rooms)
Galaxy have Admin rights (even if your system is being comprimised by low level acess for example the standard guest login rights of any windows system)

for Uplay or steam i not hear the same issues exist so i can't really say much about it.
Ya the Steam and Ubisoft so far have been claims only which is why I stated them as such, I'm sure if it was true it would have been found by now, in hindsight I probably should have not put that in the original post though.

But regardless thankfully we are not forced to use Galaxy so we can rely on the offline installers.
Does this affect Galaxy 1.2 as well, or only 2.0?
avatar
Abishia: from what i can tell (i can be wrong here)
that yea your system most be compromised but your system works on comparments (like buildings that have fire rooms)
Galaxy have Admin rights (even if your system is being comprimised by low level acess for example the standard guest login rights of any windows system)

for Uplay or steam i not hear the same issues exist so i can't really say much about it.
avatar
wolfsite: Ya the Steam and Ubisoft so far have been claims only which is why I stated them as such, I'm sure if it was true it would have been found by now, in hindsight I probably should have not put that in the original post though.

But regardless thankfully we are not forced to use Galaxy so we can rely on the offline installers.
belive it or not but there are a few games that "Request" galaxy
Anyone said NMS?.