PT-2024-35976 · Samsung · Samsung Magician
Published
2024-12-03
·
Updated
2025-06-03
·
CVE-2024-53921
CVSS v3.1
2.8
Low
| Vector | AC:L/AV:L/A:N/C:N/I:L/PR:L/S:U/UI:R |
Name of the Vulnerable Software and Affected Versions:
Samsung Magician version 8.1.0
Description:
An issue was discovered in the installer of Samsung Magician on Windows, allowing an attacker to create arbitrary folders in the system permission directory via a symbolic link during the installation process.
Recommendations:
For Samsung Magician version 8.1.0, consider avoiding the use of the installer until a patch is available, and restrict access to the system permission directory to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Magician