Executive brief
Samsung MagicINFO 9 Server, a platform used for managing digital signage and content delivery, contains a critical security flaw. This vulnerability allows an unauthorized person to remotely write files to the server with full system privileges. If exploited, an attacker could take complete control of the server, potentially leading to the display of unauthorized content, data theft, or a total service outage.
Technical details
A path traversal vulnerability (CWE-22) exists in Samsung MagicINFO 9 Server versions prior to 21.1052. The flaw stems from improper limitation of a pathname to a restricted directory, which can be exploited by a remote, unauthenticated attacker via the network. By sending specially crafted requests, an attacker can bypass directory restrictions to write arbitrary files to the underlying operating system. Successful exploitation grants the attacker the ability to execute code or modify system files with system-level privileges. This vulnerability has been observed being exploited in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Samsung MagicINFO 9 Server before 21.1052
Timeline
- 2025-05-13: disclosed: Initial disclosure by Samsung
- 2025-05-13: patched: Fixed in version 21.1052
- 2025-05-22: kev added: Added to CISA KEV catalog due to active exploitation