PT-2024-24314 · Samsung · Samsung Magician

Pwn2Car

·

Published

2024-05-09

·

Updated

2025-06-03

·

CVE-2024-31953

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Magician version 8.0.0
Description An issue was discovered that allows an attacker to escalate privileges through arbitrary code execution by tampering with the directory and executable files used during the installation process. The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.
Recommendations For Samsung Magician version 8.0.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-31953

Affected Products

Samsung Magician