CVE-2022-25154

HIGH

Samsung T5 Firmware < 1.6.9 - Uncontrolled Search Path

Title source: rule

Description

A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows 7, 10, or 11 to exploit this vulnerability.)

Scores

CVSS v3 7.3
EPSS 0.0005
EPSS Percentile 15.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

samsung/t5_firmware < 1.6.9

Timeline

Published Apr 05, 2022
Tracked Since Feb 18, 2026