CVE-2020-7811

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
12/10/2020
Last modified:
19/10/2020

Description

Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samsung:update:*:*:*:*:*:*:*:* 3.0.2.0 (including) 3.0.32.0 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*