2025年3月4日星期二

Samsung Products Multiple Vulnerabilities

Samsung Products Multiple Vulnerabilities

Release Date: 4 Mar 2025

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger data manipulation, remote code execution, denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.

 

Note:

CVE-2024-53104 is being exploited in the wild. Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. Since the exploitation requires physical connection to malicious hardware, the risk level remains Medium. 


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400
  • Galaxy Watch running Android Watch 14
  • Samsung mobile devices running Android 13, 14, 15

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


Solutions

Before installation of the software, please visit the vendor website for more details.


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Trend Micro 產品多個漏洞

Trend Micro 產品多個漏洞 發佈日期: 2025年08月07日 風險: 中度風險 類型: 保安軟件及應用設備 - 保安軟件及應用設備 ...