Out-of-Bounds Write Vulnerability in Samsung Galaxy Book Products
CVE-2023-30695
6.7MEDIUM
Key Information:
- Vendor
- Samsung
- Vendor
- CVE Published:
- 10 August 2023
Summary
An out-of-bounds write vulnerability has been identified in the Samsung Galaxy Book Series, specifically within the SSHDCPAPP TA component. This flaw affects various models including the Galaxy Book Go, Galaxy Book Go 5G, Galaxy Book2 Go, and Galaxy Book2 Pro 360, prior to a system hardware update released on July 13, 2023. A local attacker may exploit this vulnerability to execute arbitrary code, potentially compromising system integrity and user data.
Affected Version(s)
Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023"
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved