CVE-2022-33709: Input Validation
Published Jul 11, 2022
·Updated
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
Affected Software
1 affected component
Samsung Galaxy Store<4.5.41.8
Event History
Jul 11, 2022
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-33709?
CVE-2022-33709 has a medium severity level as it allows local attackers to exploit improper input validation in the Galaxy Store.
2
How do I fix CVE-2022-33709?
To mitigate CVE-2022-33709, update the Galaxy Store to version 4.5.41.8 or later.
3
What type of vulnerability is CVE-2022-33709?
CVE-2022-33709 is an improper input validation vulnerability found in the ApexPackageInstaller of the Galaxy Store.
4
Who is affected by CVE-2022-33709?
Users of the Galaxy Store prior to version 4.5.41.8 are affected by CVE-2022-33709.
5
Can CVE-2022-33709 be exploited remotely?
No, CVE-2022-33709 can only be exploited by local attackers on devices with the vulnerable version of the Galaxy Store.