Improper Integrity Check in Samsung Kies Allows Local Directory Deletion
CVE-2022-39845

5.5MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
9 September 2022

Summary

An improper validation of integrity checks in Samsung Kies, prior to version 2.6.4.22074, can be exploited by local attackers. By leveraging directory junctions, attackers can potentially delete arbitrary directories, posing a risk to data integrity and system stability. This vulnerability highlights the importance of thorough integrity validations in software applications to prevent unauthorized alterations and ensure secure operations.

Affected Version(s)

Samsung Kies < 2.6.4.22074

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.