Hackers are exploiting a remote code execution vulnerability (CVE-2024-7399) in Samsung MagicINFO 9 Server to hijack devices and deploy malware through an unauthenticated file upload feature. This vulnerability allows unauthorized access to execute arbitrary OS commands remotely. Affected: Samsung MagicINFO Server users
Keypoints :
- Vulnerability CVE-2024-7399 allows unauthorized remote code execution on Samsung MagicINFO 9 Server.
- Attackers exploit a file upload feature to upload malicious .jsp files and execute commands without authentication.
- The flaw was first disclosed in August 2024 and was addressed in version 21.1050 of the server.
- Security researchers published a proof-of-concept exploit that facilitated the vulnerabilityβs widespread exploitation shortly after its release.
- Threats include variants of Mirai botnet malware leveraging this vulnerability to compromise devices.
- Immediate action is recommended for system administrators to patch the vulnerability by upgrading to version 21.1050 or later.