CVE-2025-58481

7.3

Samsung · MotionPhoto

A local access control vulnerability in the Samsung MotionPhoto MPRemoteService allows an attacker to escalate privileges by starting a protected service.

Executive summary

A high-severity local privilege escalation vulnerability in Samsung MotionPhoto permits unauthorized access to privileged services, posing a significant risk to device integrity.

Vulnerability

This vulnerability is caused by improper access control (CWE-284) within the MPRemoteService component. It allows a locally authenticated attacker with low privileges to trigger the execution of a privileged service.

Business impact

Successful exploitation of this flaw allows a local attacker to bypass intended security restrictions and execute actions with elevated privileges. Given the CVSS score of 7.3, this represents a significant risk to the confidentiality, integrity, and availability of the affected mobile device. Compromise of this service may lead to unauthorized data access or the ability to perform administrative operations on the device.

Remediation

Immediate Action: Update the Samsung MotionPhoto application to version 4.1.51 or later via the official vendor update channel.

Proactive Monitoring: Monitor device logs for unexpected service activations or unusual process execution patterns associated with the MPRemoteService component.

Compensating Controls: Ensure that device security policies are strictly enforced and limit the installation of untrusted applications, as this vulnerability requires local access to the device to trigger.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by this vulnerability is high due to the potential for local privilege escalation. IT security teams and device administrators should prioritize the deployment of the 4.1.51 update provided by Samsung to ensure that the MPRemoteService is correctly secured. Failure to patch may allow malicious local actors to gain unauthorized control over sensitive device functions.

More Samsung CVEs

Sources