PT-2024-35976 · Samsung · Samsung Magician

Published

2024-12-03

·

Updated

2025-06-03

·

CVE-2024-53921

CVSS v3.1

2.8

Low

VectorAC:L/AV:L/A:N/C:N/I:L/PR:L/S:U/UI:R
Name of the Vulnerable Software and Affected Versions: Samsung Magician version 8.1.0
Description: An issue was discovered in the installer of Samsung Magician on Windows, allowing an attacker to create arbitrary folders in the system permission directory via a symbolic link during the installation process.
Recommendations: For Samsung Magician version 8.1.0, consider avoiding the use of the installer until a patch is available, and restrict access to the system permission directory to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-53921

Affected Products

Samsung Magician