CVE-2024-7399

HIGH KEV NUCLEI

Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)

Title source: metasploit

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

Exploits (2)

nomisec WORKING POC
by davidxbors · remote
https://github.com/davidxbors/CVE-2024-7399-POC
metasploit WORKING POC EXCELLENT
by Michael Heinzl, SSD Secure Disclosure · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/magicinfo_traversal.rb

Nuclei Templates (1)

Samsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution
HIGHVERIFIEDby iamnoooob,pdresearch
Shodan: Server: MagicInfo Premium Server

Scores

CVSS v3 8.8
EPSS 0.7100
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-04-24
VulnCheck KEV 2025-05-05
ENISA EUVD EUVD-2024-48330
CWE
CWE-22 CWE-434
Status published
Products (2)
samsung/magicinfo_9_server < 21.1050
Samsung Electronics/MagicINFO 9 Server < 21.1050
Published Aug 12, 2024
KEV Added Apr 24, 2026
Tracked Since Feb 18, 2026