CVE Published: 07/05/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: SamsungMobile |
Vendor: Samsung Mobile |
Product: Galaxy Store Status : PUBLISHED
CVE-2024-20870 Description
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
Metrics
CVSS Version: 3.1 |
Base Score: 5.1 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L