Privilege Escalation Vulnerability in Samsung Galaxy Apps by Samsung
CVE-2018-10502

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
24 September 2018

Summary

This vulnerability in Samsung Galaxy Apps allows local attackers to escalate their privileges on affected installations. The flaw arises within the handling of staging mode, where the attacker can manipulate the configuration by controlling a specific file location. To exploit this vulnerability, an attacker must first execute low-privileged code on the target system, granting them unauthorized access to protected resources. Samsung has addressed this issue in version 4.2.18.2, urging users to update to mitigate potential security risks.

Affected Version(s)

Samsung Galaxy Apps Fixed in version 4.2.18.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.