Junglewise Threat Intelligence

CVE-2026-25203: Samsung MagicINFO 9 Server local privilege escalation

CVE-2026-25203 · Severity: high · CVSS 7.8 · Published 2026-04-10

Technologies: Samsung MagicINFO 9 Server. Vendors: Samsung.

Executive brief

Samsung MagicINFO 9 Server, a content management system for digital signage and displays, contains a security vulnerability due to incorrect default permissions. A local user with low-level access could exploit this to gain higher administrative privileges on the server. This could allow an attacker to take full control of the display management system, potentially leading to unauthorized content changes or service disruption.

Technical details

A local privilege escalation vulnerability exists in Samsung MagicINFO 9 Server versions prior to 21.1091.1 due to incorrect default permissions (CWE-276). The vulnerability allows a local attacker with low-privileged access to escalate their privileges to a higher level, potentially gaining full system authority. The attack vector is local, requiring the attacker to have existing access to the server environment. Samsung has addressed this issue in the December 2025 security update by modifying the verification logic of the input and correcting permission settings.

Affected products

  • Samsung MagicINFO 9 Server less than 21.1091.1

Timeline

  • 2026-04-10: disclosed: NVD publication date
  • 2025-12: patched: Samsung released security patch SVP-DEC-2025

References