Samsung Magician vulnerabilities

8 known vulnerabilities affecting samsung/magician.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-57836HIGHCVSS 7.8≥ 6.3.0, ≤ 8.3.22026-01-05
CVE-2025-57836 [HIGH] CWE-427 CVE-2025-57836: An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.
nvd
CVE-2025-32098MEDIUMCVSS 5.3≥ 6.3.0, ≤ 8.3.02025-09-02
CVE-2025-32098 [MEDIUM] CWE-269 CVE-2025-32098: An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elev An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.
nvd
CVE-2024-53921LOWCVSS 2.8v8.1.02024-12-03
CVE-2024-53921 [LOW] CWE-276 CVE-2024-53921: An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can creat An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.
nvd
CVE-2024-36071MEDIUMCVSS 6.3v8.0.02024-06-20
CVE-2024-36071 [MEDIUM] CWE-426 CVE-2024-36071: Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the direc Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path.
nvd
CVE-2024-31953MEDIUMCVSS 6.7v8.0.02024-05-14
CVE-2024-31953 [MEDIUM] CWE-269 CVE-2024-31953: An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with th An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the prog
nvd
CVE-2024-31952MEDIUMCVSS 6.7v8.0.02024-05-14
CVE-2024-31952 [MEDIUM] CWE-59 CVE-2024-31952: An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the ins An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)
nvd
CVE-2024-23769MEDIUMCVSS 5.5v8.0.02024-02-07
CVE-2024-23769 [HIGH] CVE-2024-23769: Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) al Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.
nvd
CVE-2017-3218HIGHCVSS 8.8v5.0v<5.12017-06-21
CVE-2017-3218 [HIGH] CWE-295 CVE-2017-3218: Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.
cvelistv5nvd