Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2m8-5vfj-r2jj

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

EPSS

Процентиль: 35%
0.00147
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.7
nvd
больше 1 года назад

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

EPSS

Процентиль: 35%
0.00147
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-59