Input Validation Flaw in UEFI Firmware Affects Samsung Galaxy Book Series
CVE-2023-30738

5.5MEDIUM

What is CVE-2023-30738?

An improper input validation vulnerability exists in the UEFI firmware of Samsung's Galaxy Book series, including the Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360, and Galaxy Book Odyssey. This flaw allows a local attacker to manipulate the system and execute memory corruption in the SMM (System Management Mode), which could lead to unauthorized access or further exploitation. Affected users are encouraged to update their firmware to the latest version released in October 2023 to mitigate potential risks.

Affected Version(s)

Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey Firmware update Oct-2023 Release

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.