Samsung Notes Path Traversal Vulnerability Allows Local Attackers to Execute Arbitrary Code
CVE-2024-34656
7.8HIGH
Summary
A significant path traversal vulnerability exists in Samsung Notes, affecting versions prior to 4.4.21.62. This flaw permits local attackers to manipulate file paths, which can lead to the unauthorized execution of arbitrary code on affected devices. As a result, this weakness poses a serious risk to user data and device integrity, given the potential for exploitation by malicious actors. Samsung is urged to implement necessary security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Samsung Notes 4.4.21.62
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved