LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-4632: Samsung MagicINFO 9 Server Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 22, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 12, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-4632 to its Known Exploited Vulnerabilities catalog on May 22, 2025, with a federal patch deadline of Jun 12, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.

CVE-2025-4632 is a path traversal vulnerability in Samsung MagicINFO 9 Server. It allows an attacker to write arbitrary files with system-level authority. This matters because successful abuse can let an attacker plant files that enable further control of the server, potentially affecting digital signage management systems and any connected infrastructure.

Defenders should treat this as a high-priority issue for any environment running the product, confirm details against the vendor advisory, and follow CISA guidance to apply mitigations or discontinue use if fixes are unavailable.

How it works

The flaw is classified as CWE-22, improper limitation of a pathname to a restricted directory (path traversal). In products of this class, user-supplied input that influences file paths is not adequately sanitized. An attacker can craft requests that escape the intended directory and write files to arbitrary locations on the system.

According to the CISA summary, the vulnerability in Samsung MagicINFO 9 Server specifically permits writing arbitrary files as system authority. This means the write operation occurs with elevated privileges rather than a limited application account. Exact request formats, parameters, or exploit sequences are not detailed here; technical teams must review the vendor advisory for the precise attack surface and conditions required for abuse. No public details indicate ransomware use of this CVE.

Am I affected? How to find it in your systems

Samsung MagicINFO 9 Server is typically deployed as a management platform for digital signage, content scheduling, and display control. It commonly runs on Windows or Linux servers in corporate, retail, education, or public-sector networks that operate large numbers of screens.

To inventory:

Version and configuration specifics are not provided in the available facts; confirm the exact affected builds and any required configuration states against the vendor advisory. Look for signs of exploitation in application logs, web server access logs, and file-system audit trails: unexpected file creation or modification outside the normal MagicINFO data directories, especially files written with system-level ownership or in sensitive system paths. Correlate with anomalous authentication or HTTP requests that contain directory traversal sequences (for example, sequences that attempt to leave the web root). Endpoint detection and response tools can flag unusual process activity originating from the MagicINFO service account.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions for Samsung MagicINFO 9 Server as soon as they are available and validated in your environment. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations cannot be implemented.

After patching, perform these hardening steps common to path-traversal issues:

Document the change and retain evidence of the update for compliance and audit purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule the permanent fix promptly.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full system compromise and subsequent data exposure or lateral movement. Review logs for indicators of successful file writes and investigate any suspicious activity. If compromise is confirmed or suspected, follow your incident-response plan, isolate affected hosts, and preserve evidence. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or other information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSamsung · MagicINFO 9 Server
WeaknessCWE-22
Added to CISA KEVMay 22, 2025
Federal patch deadlineJun 12, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities