Skip to content
COOEY

EXPOSURES › CVE-2024-7399

CVE-2024-7399

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-7399 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildunpatched

Samsung MagicINFO 9 Server path traversal vulnerability allows attackers to write arbitrary files as system authority.

This vulnerability enables attackers to write files as system authority, potentially leading to privilege escalation or system compromise. DIB organizations should audit Samsung MagicINFO 9 Server deployments and apply patches immediately to prevent unauthorized file system access.

Shame score — A known path traversal vulnerability that allows file writing as system authority, though not directly RCE, poses significant security risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.