Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
History

Wed, 24 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Samsung
Samsung quick Share
Weaknesses CWE-22
CPEs cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Samsung
Samsung quick Share

Tue, 03 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 06:00:00 +0000

Type Values Removed Values Added
Description Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published: 2024-12-03T05:48:06.555Z

Updated: 2024-12-03T14:25:22.984Z

Reserved: 2024-10-15T05:26:08.661Z

Link: CVE-2024-49421

cve-icon Vulnrichment

Updated: 2024-12-03T14:25:18.310Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-03T06:15:10.393

Modified: 2025-09-24T19:18:12.197

Link: CVE-2024-49421

cve-icon Redhat

No data.