CVE-2024-36071

MEDIUM

Samsung Magician 8.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path.

Scores

CVSS v3 6.3
EPSS 0.0010
EPSS Percentile 27.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (1)
samsung/magician 8.0.0
Published Jun 20, 2024
Tracked Since Feb 18, 2026