Samsung MagicINFO 9 Server RCE flaw now exploited in attacks

Samsung MagicINFO 9 Server RCE flaw now exploited in attacks

Hackers are exploiting a remote code execution vulnerability (CVE-2024-7399) in Samsung MagicINFO 9 Server to hijack devices and deploy malware through an unauthenticated file upload feature. This vulnerability allows unauthorized access to execute arbitrary OS commands remotely. Affected: Samsung MagicINFO Server users

Keypoints :

  • Vulnerability CVE-2024-7399 allows unauthorized remote code execution on Samsung MagicINFO 9 Server.
  • Attackers exploit a file upload feature to upload malicious .jsp files and execute commands without authentication.
  • The flaw was first disclosed in August 2024 and was addressed in version 21.1050 of the server.
  • Security researchers published a proof-of-concept exploit that facilitated the vulnerability’s widespread exploitation shortly after its release.
  • Threats include variants of Mirai botnet malware leveraging this vulnerability to compromise devices.
  • Immediate action is recommended for system administrators to patch the vulnerability by upgrading to version 21.1050 or later.

Read More: https://www.bleepingcomputer.com/news/security/samsung-magicinfo-9-server-rce-flaw-now-exploited-in-attacks/