CVE-2022-24927

MEDIUM

Samsung Video Player < 7.3.15.30 - Unauthenticated Arbitrary Video Execution

Title source: llm
STIX 2.1

Description

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.

References (1)

Core 1
Core References

Scores

CVSS v3 4.2
EPSS 0.0014
EPSS Percentile 34.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-269
Status published
Products (1)
samsung/video_player < 7.3.15.30
Published Feb 11, 2022
Tracked Since Feb 18, 2026