Cyber Posture

CVE-2025-20914

Medium

Published: 06 March 2025

Published
06 March 2025
Modified
17 July 2025
KEV Added
Patch
CVSS Score 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0023 45.8th percentile
Risk Priority 11 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Security Summary

CVE-2025-20914 is an out-of-bounds read vulnerability (CWE-125) in the application of binary handwriting content within Samsung Notes versions prior to 4.4.26.71. Published on 2025-03-06 with a CVSS v3.1 base score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), the flaw occurs during processing that exposes memory beyond allocated bounds.

Local attackers with low privileges on the affected device can exploit this vulnerability with low complexity and no user interaction required. Exploitation enables reading of sensitive out-of-bounds memory content, resulting in high confidentiality impact while leaving integrity and availability unaffected.

Samsung's security advisory at https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03 provides details on the vulnerability, with mitigation achieved by updating Samsung Notes to version 4.4.26.71 or later.

Details

CWE(s)
CWE-125

Affected Products

samsung
notes
≤ 4.4.26.71

MITRE ATT&CK Enterprise Techniques

T1005 Data from Local System Collection
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Why these techniques?

The out-of-bounds read in Samsung Notes enables local attackers to access sensitive memory content on the device, directly facilitating collection of data from local system sources.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

References