PT-2019-14602 · Samsung · Samsungtts
Flanker017
·
Published
2019-09-25
·
Updated
2024-03-23
·
CVE-2019-16253
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SamsungTTS versions prior to 3.0.02.7
SamsungTTS version 3.0.00.101
Description
The issue allows a local attacker to escalate privileges, for example, to system privileges. It is related to the handling of debugging flags by the package manager binary. There is an estimated exploit that uses this issue as a payload.
Recommendations
For SamsungTTS versions prior to 3.0.02.7, update to version 3.0.02.7 or later.
For SamsungTTS version 3.0.00.101, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the package manager binary until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsungtts