ZeroHour

CVE-2024-31952

CVSS 3.1
6.7 medium
EPSS
<1%p7
Published
()
Modified
Description

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

Vendors
samsung
Products
magician
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.