Vulnerabilities > CVE-2020-7811 - Deserialization of Untrusted Data vulnerability in Samsung Update

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
samsung
CWE-502

Summary

Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication

Vulnerable Configurations

Part Description Count
Application
Samsung
1
OS
Microsoft
1

Common Weakness Enumeration (CWE)