CVE-2025-57836: High severity Samsung Magician vulnerability
Published Jan 5, 2026
·Updated
An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.
Affected Software
3 affected components
Samsung Magician>=6.3.0<=8.3.2
All of the following
Samsung Magician>=6.3.0<=8.3.2
Microsoft Windows
Event History
Jan 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57836?
CVE-2025-57836 is considered a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2025-57836?
To fix CVE-2025-57836, update Samsung Magician to the latest version beyond 8.3.2.
3
What systems are affected by CVE-2025-57836?
CVE-2025-57836 affects Samsung Magician versions from 6.3.0 to 8.3.2 on Windows.
4
What type of vulnerability is CVE-2025-57836?
CVE-2025-57836 is a privilege escalation vulnerability resulting from weak permissions during installation.
5
Can non-admin users exploit CVE-2025-57836?
Yes, non-admin users can exploit CVE-2025-57836 due to the DLL hijacking risk associated with weak permissions set by the installer.