CVE-2024-31954

An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31954/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31954/ -

03 Jul 2024, 01:55

Type Values Removed Values Added
CWE CWE-538
Summary
  • (es) Se descubrió un problema en el instalador de Samsung Portable SSD para T5 1.6.10 en Windows. Debido a que es posible alterar el directorio y los archivos DLL utilizados durante el proceso de instalación, un atacante puede aumentar los privilegios mediante la ejecución de código arbitrario. (Un atacante ya debe tener privilegios de usuario)

14 May 2024, 15:30

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:30

Updated : 2024-11-21 09:14


NVD link : CVE-2024-31954

Mitre link : CVE-2024-31954

CVE.ORG link : CVE-2024-31954


JSON object : View

Products Affected

No product.

CWE
CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory