PT-2026-1297 · Samsung · Samsung Magician

CVE-2025-57836

·

Publicado

2025-08-11

·

Atualizado

2026-01-07

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Magician versions 6.3.0 through 8.3.2
Description The software installer creates a temporary folder with insufficient permissions during the installation process on Windows. This allows a non-administrative user to potentially perform DLL hijacking and gain elevated privileges.
Recommendations Versions prior to 6.3.0 are not affected. Versions 6.3.0 through 8.3.2 are affected and require attention.

Correção

LPE

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00632
CVE-2025-57836

Produtos afetados

Samsung Magician