Input validation error in Samsung products - CVE-2023-30738

 

Input validation error in Samsung products - CVE-2023-30738

Published: October 4, 2023


Vulnerability identifier: #VU81469
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30738
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input in UEFI Firmware. A local attacker can pass specially crafted input to the application and execute SMM memory corruption.


Affected software

Galaxy Book
Galaxy Book Pro
Galaxy Book Pro 360
Galaxy Book Odyssey

How to mitigate CVE-2023-30738

Install updates from vendor's website.

Galaxy Book - update to Oct-2023
Galaxy Book Pro - update to Oct-2023
Galaxy Book Pro 360 - update to Oct-2023
Galaxy Book Odyssey - update to Oct-2023

External References

Related Security Bulletins