Samsung Notes Path Traversal Vulnerability Allows Local Attackers to Execute Arbitrary Code
CVE-2024-34656

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 September 2024

Summary

A significant path traversal vulnerability exists in Samsung Notes, affecting versions prior to 4.4.21.62. This flaw permits local attackers to manipulate file paths, which can lead to the unauthorized execution of arbitrary code on affected devices. As a result, this weakness poses a serious risk to user data and device integrity, given the potential for exploitation by malicious actors. Samsung is urged to implement necessary security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Samsung Notes 4.4.21.62

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.