CVE-2025-20974 Details
Description
Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.
A vulnerability exists in Samsung PackageInstallerCN prior to version 15.0.11.0, where improper handling of insufficient permissions allows local attackers to bypass user interaction for installation requests.
Users can update to version 15.0.11.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 7, 2025CISA-ADP
Assessed May 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Samsung PackageInstallerCN | < 15.0.11.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2025 | New CVE Received | [email protected] |
Volerion