Vulnerability Description
An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Magician | >= 6.3.0, <= 8.3.2 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://semiconductor.samsung.com/support/quality-support/product-security-updatVendor Advisory
- https://semiconductor.samsung.com/support/quality-support/product-security-updatVendor Advisory
FAQ
What is CVE-2025-57836?
CVE-2025-57836 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL...
How severe is CVE-2025-57836?
CVE-2025-57836 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57836?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Magician, Microsoft Windows.