CVE-2026-25203
7.8Samsung · MagicINFO 9 Server
Samsung MagicINFO 9 Server contains a local privilege escalation vulnerability due to incorrect default permissions, allowing low-privileged users to gain elevated access.
Executive summary
Samsung MagicINFO 9 Server is affected by a local privilege escalation vulnerability that allows authenticated local users to gain elevated system privileges.
Vulnerability
The software suffers from incorrect default permissions (CWE-276), which can be exploited by a local user with low privileges to achieve full system compromise. The vulnerability requires local access and does not require user interaction to trigger.
Business impact
Successful exploitation of this vulnerability allows a local attacker to escalate their privileges to the highest level, potentially resulting in full system control. Given the CVSS score of 7.8, this poses a significant risk to the confidentiality, integrity, and availability of the host server and any data managed by the MagicINFO platform.
Remediation
Immediate Action: Update Samsung MagicINFO 9 Server to version 21.1091.1 or later as specified by the vendor security advisory.
Proactive Monitoring: Review system logs for unauthorized privilege changes or unusual activity initiated by local user accounts.
Compensating Controls: Implement strict access control lists on the host operating system to limit the ability of non-privileged users to interact with the MagicINFO installation directory.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this local privilege escalation vulnerability necessitates prompt attention to prevent unauthorized administrative access. Organizations running Samsung MagicINFO 9 Server should prioritize applying the patch to version 21.1091.1 to mitigate this risk immediately.