Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=4 | vendor advisory |