ZeroHour

CVE-2024-7399

KEVmoderate

Unauthenticated Path Traversal File Write in Samsung MagicINFO 9 Server

CISA: Samsung MagicINFO 9 Server Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

CVE-2024-7399 is a critical path-traversal flaw (CWE-22, tracked alongside CWE-434 unrestricted file upload) in Samsung MagicINFO 9 Server, Samsung's on-premises digital signage content-management platform, affecting all versions before 21.1050. Because the server fails to properly constrain a user-supplied pathname, an unauthenticated remote attacker (CVSS: AV:N/AC:L/PR:N/UI:N) can submit a crafted path and have arbitrary files written outside the intended directory with system authority — typically enabling webshell or malicious payload placement and, in practice, full server compromise. Any organization running an affected MagicINFO 9 Server instance, especially one reachable from the internet, is exposed. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-24 with a May 2026 federal patching deadline, EPSS assigns a 91.9% probability of exploitation within 30 days (100th percentile), and recent reporting describes threat actors exploiting MagicINFO 9 Server flaws — this traversal and the related CVE-2025-4632 — to deploy the Mirai botnet, though accounts of which specific CVE is in use have been mixed.

What to do: Upgrade MagicINFO 9 Server to version 21.1050 or later per Samsung's advisory; as interim mitigation, restrict internet exposure of the server and inspect the host for unexpected files, webshells, or dropped binaries (e.g., Mirai artifacts) indicating post-exploitation. Federal agencies under BOD 22-01 must apply the update or remove the product by the May 2026 KEV deadline; given the near-certain EPSS score and confirmed in-the-wild use — despite no known public PoC — treat this as a priority patch.

Affected
Samsung MagicINFO 9 Serverall versions before 21.1050
Estimated exposure
moderatelikely on the order of thousands of internet-exposed MagicINFO 9 Server instances; total on-premises installed base unknown — MagicINFO 9 is a per-site digital signage management server deployed by signage operators and enterprises rather than consumer-scale software, and only a fraction of such instances is typically exposed directly to the internet, so directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

CISA Known Exploited Vulnerability
Affected
Samsung MagicINFO 9 Server
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
samsung
Products
magicinfo 9 server
Weakness
CWE-22, CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news