PT-2024-24314 · Samsung · Samsung Magician
Pwn2Car
·
Published
2024-05-09
·
Updated
2025-06-03
·
CVE-2024-31953
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Magician version 8.0.0
Description
An issue was discovered that allows an attacker to escalate privileges through arbitrary code execution by tampering with the directory and executable files used during the installation process. The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.
Recommendations
For Samsung Magician version 8.0.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Magician