PT-2020-19808 · Samsung · Samsung Update

Yong Hwi

·

Published

2020-10-12

·

Updated

2020-10-19

·

CVE-2020-7811

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Update versions 3.0.2.0 through 3.0.32.0
Description The issue allows for privilege escalation due to the execution of crafted commands by an attacker during the deserialization of data received through inter-process communication.
Recommendations For Samsung Update versions 3.0.2.0 through 3.0.32.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7811

Affected Products

Samsung Update