Security News Samsung patches high-risk security vulnerability in its SSD software, update yours now

Parkinsond

Level 62
Thread author
Verified
Well-known
Dec 6, 2023
5,051
14,221
6,069
If you have a Samsung SSD in your computer and you use the Samsung Magician app, it is time to update to the latest version, as Samsung reported a high-severity vulnerability in some of the older versions of the program.

The South Korean tech giant published details about CVE-2025-57836 on its official website, revealing that Samsung Magician app versions from 6.3.0 all the way to 8.3.2 have a security vulnerability that allows privilege escalation and DLL hijacking. In other words, someone can use the Samsung Magician app to gain admin privileges and then do anything they want with your PC by placing infected files into the app's folder with weak security.

Samsung patched the vulnerability in Magician version 9.0 and newer.

 
Recommendation / Remediation

Priority 1

Immediate Update You must update the software to a patched version to mitigate this risk.

Verify Version
Open Samsung Magician and check if the version is between 6.3.0 and 8.3.2.

Install Patch
Update to Samsung Magician version 9.0 (or newer) immediately.

This update patches the vulnerability and introduces a redesigned UI.

Source
Download the update directly from the official Samsung Semiconductor website to ensure integrity.

Priority 2
Principle of Least Privilege

Ensure that standard user accounts on the machine do not have unnecessary write access to system directories, though this specific exploit targets a temporary folder created by the installer itself.

Sources & References

Official Vendor Source (Patch & Advisory)

Samsung Semiconductor Support

This is the official location to download the patched version (9.0 or higher) of the Samsung Magician software.

URL:
 
My theory is the less programs & or extensions you have the less there is to go wrong...
Another reason to use Crystal disk info; if I stick to the manfacturer software and have for example 3 drives of different vendors in my PC, I need to install 3 different programs, larger attack surface area.
 
  • Like
Reactions: Sorrento
Besides drive health; what would be the reason to run the Samsung SSD software?
It's claimed that manfacturer own software is more precise than 3rd party ones.
Also, isn't windows built in drive health monitoring sufficient?
W 11 24h2 lacks this feature, or may be my drives are too old and not supported for.
 
Samsung makes great hardware and terrible software. Simple rule is to never ever use Samsung software. Get the hardware then don't ever connect or update. Samsung Magician is not only bad for security but the firmware updates for drives often nerf speeds. Be careful.
 
Samsung makes great hardware and terrible software. Simple rule is to never ever use Samsung software. Get the hardware then don't ever connect or update. Samsung Magician is not only bad for security but the firmware updates for drives often nerf speeds. Be careful.
There stable version of Windows browser is not bad; the main downside is being based on an old Chromium version.