Input validation error in Samsung products - CVE-2023-30738
Published: October 4, 2023
Vulnerability identifier: #VU81469
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30738
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in UEFI Firmware. A local attacker can pass specially crafted input to the application and execute SMM memory corruption.
Affected software
Galaxy Book
Galaxy Book Pro
Galaxy Book Pro 360
Galaxy Book Odyssey
Galaxy Book Pro
Galaxy Book Pro 360
Galaxy Book Odyssey
How to mitigate CVE-2023-30738
Install updates from vendor's website.
Galaxy Book - update to Oct-2023
Galaxy Book Pro - update to Oct-2023
Galaxy Book Pro 360 - update to Oct-2023
Galaxy Book Odyssey - update to Oct-2023
Galaxy Book Pro - update to Oct-2023
Galaxy Book Pro 360 - update to Oct-2023
Galaxy Book Odyssey - update to Oct-2023