CVE-2022-28790

MEDIUM

Link to Windows Service <2.3.04.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

References (1)

Core 1
Core References

Scores

CVSS v3 4.0
EPSS 0.0006
EPSS Percentile 17.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-287
Status published
Products (1)
samsung/link_to_windows_service < 2.3.04.1
Published May 03, 2022
Tracked Since Feb 18, 2026