CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-04-24. EPSS: 91.9% chance of exploitation in the next 30 days.
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
Affected products
- Samsung MagicINFO 9 Server: before 21.1050.0 (fixed in 21.1050.0)
Published 2024-08-12. Last modified 2026-10-01.