Privileged Activities Attack via Improper Input Validation
CVE-2024-49401
7.1HIGH
Summary
A vulnerability exists in Samsung's Settings Suggestions feature, where improper input validation can allow local attackers to carry out privileged activities. This flaw enhances the attack surface for potential exploits, emphasizing the need for prompt updates. Affected devices prior to the SMR Nov-2024 Release 1 version are particularly at risk, highlighting the importance of maintaining up-to-date security protocols. For further details, refer to the Samsung Mobile Security Update documentation.
Affected Version(s)
Samsung Mobile Devices SMR Nov-2024 Release in Android 13, 14
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved