
Cloud Vulnerability DB
A community-led vulnerabilities database
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to access sensitive information via changing the path. The vulnerability, identified as CVE-2021-25392, affects Samsung devices running Samsung Dex and was discovered in early 2021 (MITRE CVE, NVD).
The vulnerability exists in the notification policy file handling of Samsung DeX System UI (com.samsung.desktopsystemui). It allows attackers to steal notification policy configuration through improper path protection (Oversecured Blog, Samsung Mobile).
The vulnerability enables attackers to access sensitive information from user notifications, which could include chat descriptions from messaging apps like Telegram, folder information from Google Docs, and email details from Samsung Email and Gmail inboxes (Hacker News).
Samsung addressed this vulnerability in the May 2021 Security Maintenance Release (SMR). Users should update their devices to a version with SMR MAY-2021 Release 1 or later to protect against this vulnerability (Samsung Mobile).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."