CVE-2022-39909

HIGH

Samsung Gear IconX PC Manager < 2.1.221019.51 - Arbitrary File Creation via Symbolic Link

Title source: llm
STIX 2.1

Description

Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0003
EPSS Percentile 9.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-345
Status published
Products (1)
samsung/gear_iconx_pc_manager < 2.1.221019.51
Published Dec 08, 2022
Tracked Since Feb 18, 2026