ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Confusion Reigns as Threat Actors Exploit Samsung MagicInfo Flaw

criticalThreat actor exploited in the wildimportance 60CVE-2024-7399

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-7399
Unauthenticated Path Traversal File Write in Samsung MagicINFO 9 Server

CVE-2024-7399 is a critical path-traversal flaw (CWE-22, tracked alongside CWE-434 unrestricted file upload) in Samsung MagicINFO 9 Server, Samsung's on-premises digital signage content-management platform, affecting all versions before 21.1050. Because the server fails to properly constrain a user-supplied pathname, an unauthenticated remote attacker (CVSS: AV:N/AC:L/PR:N/UI:N) can submit a crafted path and have arbitrary files written outside the intended directory with system authority — typically enabling webshell or malicious payload placement and, in practice, full server compromise. Any organization running an affected MagicINFO 9 Server instance, especially one reachable from the internet, is exposed. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-24 with a May 2026 federal patching deadline, EPSS assigns a 91.9% probability of exploitation within 30 days (100th percentile), and recent reporting describes threat actors exploiting MagicINFO 9 Server flaws — this traversal and the related CVE-2025-4632 — to deploy the Mirai botnet, though accounts of which specific CVE is in use have been mixed.

Do: Upgrade MagicINFO 9 Server to version 21.1050 or later per Samsung's advisory; as interim mitigation, restrict internet exposure of the server and inspect the host for unexpected files, webshells, or dropped binaries (e.g., Mirai artifacts) indicating post-exploitation. Federal agencies under BOD 22-01 must apply the update or remove the product by the May 2026 KEV deadline; given the near-certain EPSS score and confirmed in-the-wild use — despite no known public PoC — treat this as a priority patch.

9.892% KEV
  • Samsung MagicINFO 9 Server all versions before 21.1050
moderatelikely on the order of thousands of internet-exposed MagicINFO 9 Server instances; total on-premises installed base unknown
Full article400 words · extracted from infosecurity-magazine.com · click to collapse

Administrators of Samsung MagicInfo 9 Server have been urged to air gap their systems from the internet after researchers spotted exploit attempts impacting a recently updated version.

The Samsung product is described as a hub for managing the tech giant’s popular digital signage displays, which are found in many public locations like airports, as well as corporate offices.

However, there’s some confusion about whether the latest attacks are exploiting a bug first disclosed and patched last year (CVE-2024-7399), or a zero-day vulnerability found in January by a researcher working with SSD Disclosure.

The latter vulnerability, or collection of bugs, allow “an unauthenticated user to upload a web shell and achieve remote code execution under the Apache Tomcat process,” according to Huntress.

Read more on Samsung zero-days: Google Exposes 18 Zero-Day Flaws in Samsung Exynos Chips

The flaws are said to affect MagicInfo 9 Server 21.1050.0 – the latest version of the server. However, they are apparently very similar to CVE-2024-7399, which was published in August 2024. In fact, they are so similar that, when reported to Samsung, the vendor registered them as a duplicate issue and appeared to take no further action.

As a result, SSD Disclosure published a proof-of-concept exploit in line with its 90-day disclosure window, back on April 30.

Within days, Arctic Wolf spotted what it claimed to be exploits of CVE-2024-7399, saying that the affected systems were versions prior to 21.1050.

“This was quickly picked up by media outlets with the same narrative that systems running version 21.1050 were safe,” explained Huntress in a blog post.

“Huntress also observed exploitation in the wild; however, some of the systems impacted had the latest available patch, which strengthened the assumption that the latest available version (21.1050.0) was indeed still vulnerable, as mentioned by SSD Disclosure.”

The bottom line is that version 21.1050.0 and 21.1040.2 of MagicInfo 9 Server are still vulnerable, and no patches are available, according to Huntress.

“It can only be concluded that the patch from August 2024 was either incomplete or for a separate, but similar, vulnerability,” the security vendor concluded.

“Huntress has reached out to the team at Samsung, notifying them of this, but at the time of writing, is yet to receive a response.”

The advice for MagicInfo 9 Server administrators is therefore that they ensure any installations aren’t internet facing, until a proper patch has been released.

Image credit: JHVEPhoto / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/threat-actors-exploit-samsung/