CVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- May 13, 2025
- Published Date
- May 13, 2025
- Last Updated
- May 22, 2025
- Vendor
- Samsung Electronics
- Product
- MagicINFO 9 Server
- Description
- Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
- Tags
- Score
- 57.86% (Percentile: 98.03%) as of 2025-06-12
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
- Exploited in the Wild
- Yes (2025-05-14 18:15:36 UTC) Source
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
SSVC Information
Exploit Status
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
TheHackerNews | 2025-05-14 18:15:29 UTC |
Recent Mentions
CISA Adds One Known Exploited Vulnerability to Catalog
Source: All CISA Advisories • Published: 2025-05-22 12:00:00 UTC
Attackers Target Samsung MagicINFO Server Bug, Patch Now
Source: Dark Reading • Published: 2025-05-15 19:10:38 UTC
Follow-Up: Samsung Patches Zero-Day Vulnerability in MagicINFO 9 Server (CVE-2025-4632)
Source: Arctic Wolf • Published: 2025-05-14 20:39:36 UTC
Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit
Source: TheHackerNews • Published: 2025-05-14 17:57:00 UTC
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel