First published: Thu Dec 08 2022(Updated: )
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Gear IconX PC Manager | <2.1.221019.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39909 is classified as a medium severity vulnerability due to potential local exploitation.
To fix CVE-2022-39909, update Samsung Gear IconX PC Manager to version 2.1.221019.51 or later.
Users of Samsung Gear IconX PC Manager prior to version 2.1.221019.51 are affected by CVE-2022-39909.
CVE-2022-39909 allows local attackers to create arbitrary files using symbolic links.
There is no official workaround for CVE-2022-39909, and updating is the recommended course of action.