Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-33711

Description

Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction.

POC

Reference

- https://security.samsungmobile.com/serviceWeb.smsb?year==2022&month=07

Github

- https://github.com/dlehgus1023/dlehgus1023

- https://github.com/l33d0hyun/l33d0hyun