# CVE-2018-10498

## Summary

- **CVE ID:** CVE-2018-10498
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-37
- **Published:** Sep 24, 2018
- **Last Modified:** Mar 14, 2026

## Description

This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of file:/// URIs. The issue lies in the lack of proper validation of user-supplied data, which can allow for reading arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges. Was ZDI-CAN-5329.

## Affected Products

- Samsung — Samsung Email (Fixed in version 5.0.02.16)

## References

- [CNA](https://zerodayinitiative.com/advisories/ZDI-18-557)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.06%
- **EPSS Percentile:** 18.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._