Privilege Escalation Vulnerability in Samsung Galaxy Apps by Samsung
CVE-2018-10502
7.8HIGH
Summary
This vulnerability in Samsung Galaxy Apps allows local attackers to escalate their privileges on affected installations. The flaw arises within the handling of staging mode, where the attacker can manipulate the configuration by controlling a specific file location. To exploit this vulnerability, an attacker must first execute low-privileged code on the target system, granting them unauthorized access to protected resources. Samsung has addressed this issue in version 4.2.18.2, urging users to update to mitigate potential security risks.
Affected Version(s)
Samsung Galaxy Apps Fixed in version 4.2.18.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved