Known Exploited Vulnerabilities CVE-2025-4632

Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CVE-2025-4632 Samsung MagicINFO 9 Server Path Traversal Vulnerability exploitation_technique T1068 Exploitation for Privilege Escalation
Comments
By exploiting a path traversal vulnerability in Samsung MagicINFO 9 Server, an unauthenticated attacker can write arbitrary files with system privileges. This can be used to deploy malware or to hijack resources for activity such as cryptocurrency mining.
References
CVE-2025-4632 Samsung MagicINFO 9 Server Path Traversal Vulnerability primary_impact T1059 Command and Scripting Interpreter
Comments
By exploiting a path traversal vulnerability in Samsung MagicINFO 9 Server, an unauthenticated attacker can write arbitrary files with system privileges. This can be used to deploy malware or to hijack resources for activity such as cryptocurrency mining.
References
CVE-2025-4632 Samsung MagicINFO 9 Server Path Traversal Vulnerability secondary_impact T1496 Resource Hijacking
Comments
By exploiting a path traversal vulnerability in Samsung MagicINFO 9 Server, an unauthenticated attacker can write arbitrary files with system privileges. This can be used to deploy malware or to hijack resources for activity such as cryptocurrency mining.
References
CVE-2025-4632 Samsung MagicINFO 9 Server Path Traversal Vulnerability secondary_impact T1608.001 Upload Malware
Comments
By exploiting a path traversal vulnerability in Samsung MagicINFO 9 Server, an unauthenticated attacker can write arbitrary files with system privileges. This can be used to deploy malware or to hijack resources for activity such as cryptocurrency mining.
References