CVE-2025-4632Active Exploitation(samsung / magicinfo_9_server)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch samsung magicinfo_9_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magicinfo_9_server

Threat summary

  • Active exploitation appears in 6 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-09-24); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Vendors
Products
magicinfo_9_server

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-03-29: 1Mentions · 2026-04-24: 1Mentions · 2026-05-07: 1Mentions · 2026-09-24: 2Mentions · 2026-09-25: 1Mentions · 2026-09-27: 1Mentions · 2026-10-01: 1Mentions · 2026-10-05: 1Exploit Tool / Code · 2026-09-24: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-09-24: 2Active Exploitation · 2026-09-25: 1Active Exploitation · 2026-09-27: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-09-25: 1Patch / Workaround · 2026-09-27: 1Technical Details · 2026-04-24: 1Technical Details · 2026-05-07: 1Technical Details · 2026-09-24: 1Technical Details · 2026-09-27: 103-2904-2405-0709-2409-2509-2710-0110-05
Signal classification3 categories
Active Exploitation
571.4%
Disclosure
114.3%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-291
Active Exploitation1
2026-04-241
Disclosure1
2026-05-071
Patch1
2026-09-242
Active Exploitation2
2026-09-251
Active Exploitation1
2026-09-271
Active Exploitation1
Full discourse9 posts
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️🇪🇸 A dataset of http://Fluchos.com, a Spanish footwear brand based in Arnedo (La Rioja) known for handmade leather shoes since 1962, has allegedly been leaked on a popular cybercrime forum. ▪️ Records: ~135,000 lines ▪️ Exploit Used: CVE-2025-4632 (MSSQL DB, small network) ▪️ Data Fields: Full name, phone, email The poster notes the server was also compromised by a crypto miner, suggesting prior exploitation by another party.

    Post summary

    The tweet reports an active exploitation of a small MSSQL database using CVE-2025-4632, resulting in a data leak and the deployment of a crypto miner on the compromised server.

    110040187.6K
    187.2K followersView on X
  • Brahim@IBthecoder
    Active Exploitation

    Hackers exploited a Samsung flaw then BUILT their cryptominer on the victim’s own computer. That unusual move created so much activity that it helped security researchers spot the attack. Here’s what happened: Attackers exploited CVE-2025-4632, a critical vulnerability in Samsung MagicINFO 9 Server that can allow attackers to write files with system-level privileges. Samsung released a fix in May 2025. But in September 2026, Huntress investigated an intrusion where the vulnerability was used to gain access to a Windows system running MagicINFO. Once inside, the attackers: Tried to install AnyDesk for remote access Created a new local administrator account Disabled Microsoft Defender Launched a Monero mining tool Compiled the miner directly on the victim's machine And that last step is what makes this attack especially interesting. Instead of simply dropping a finished cryptominer, the attackers used a miner builder and several Windows development tools and compilers to create it on the compromised endpoint. That generated a noisy process chain that defenders could see in endpoint telemetry. The resulting miner then connected to a public mining pool and used the victim's computing resources to mine Monero. Huntress also observed the attackers making multiple attempts to download AnyDesk. Microsoft Defender blocked the first attempts before the attackers eventually succeeded. And there's another important lesson here: The vulnerability had already been patched. This wasn't necessarily about discovering a brand-new zero-day. It shows what can happen when internet-facing software remains vulnerable long after a security update is available. For defenders, the warning signs weren't just the final miner. They included: Unexpected remote-access software New administrator accounts Security tools being disabled Sudden compiler activity Unknown programs running from user directories Unexpected connections to cryptocurrency mining pools Attackers don't always hide by doing less. Sometimes they hide by doing something unusual enough that nobody immediately understands what they're seeing. If you run Samsung MagicINFO, check that your installation is patched and avoid exposing vulnerable management servers directly to the internet. https://cybersecuritynews.com/samsung-flaw/

    Post summary

    CVE-2025-4632 was actively exploited in September 2026 to compromise a Samsung MagicINFO server, enabling attackers to deploy cryptomining malware. While Samsung released a fix in May 2025, the vulnerability remained exploitable in unpatched systems exposed to the internet.

    00050228
    409 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    A threat actor exploited Samsung MagicINFO CVE-2025-4632 to deploy a Monero miner compiled live on the victim endpoint using SilentXMRMiner Builder, generating unusually noisy EDR telemetry. Key findings: - Initial access came through CVE-2025-4632, an arbitrary file write as SYSTEM in Samsung MagicINFO Premium running on Apache Tomcat. The parent process tomcat9.exe is your pivot point: any cmd.exe or PowerShell spawned from it is post-exploitation. The actor hit the same vector twice, eight days apart, after the first incident was reported but not fully remediated. - AnyDesk was pulled three times from 194.87.89[.]30:8899 via certutil, then Invoke-WebRequest, then a third method that evaded Defender. A local account named oldadministrator was created, sharing the password F@x2020!@# with AnyDesk. Defender was then disabled via SystemSettingsAdminFlows.exe to clear the way for compilation. - The build chain under Silent XMR Miner Builder.exe spawned csc.exe, cvtres.exe, donut.exe, tcc.exe, cc1.exe, and gcc.exe as child processes. All compilers ran under an unsigned parent, which is a high-fidelity hunt signal even without knowing the final payload. - The resulting miner (SHA256: 0d202e16408770e8b6cceb14e1e3e72946b154bf881d27fe33d0060315b30dd1) injected into explorer.exe and connected to auto.c3pool[.]org:19999. Explorer.exe with XMRig mining arguments is never legitimate. #DFIR_Radar

    Post summary

    The text reports active exploitation of CVE-2025-4632 by a threat actor, with detailed post-exploitation behavior and tooling used to deploy a Monero miner. The central focus is real-world abuse rather than patching, PoC sharing, or false-positive clarification.

    10000174
    2.0K followersView on X
  • P.K. Sharma@_pksharma

    A Samsung signage flaw at least 476 days old led to AnyDesk on try three and a miner built on the host 499 days. 3 tries. 8 days. Those numbers are most of what Huntress published about a Samsung signage server incident in early September 2026. 499 days is the age of the CVE record for CVE-2025-4632 (MagicINFO 9 Server, published 13 May 2025) on the day of Huntress's write-up, 24 September 2026. At least 476 days had passed when the incident began (derived). 🧮 Samsung scored the flaw 9.8 as the CVE numbering authority. CISA listed it as exploited on 22 May 2025, with a due date of 12 June 2025. Huntress says the activity was "reportedly associated" with it. 3 tries is how many times the attacker needed to download AnyDesk: Defender removed the first two. The third worked, then came a new local administrator account and a disabled Defender. 8 days is the gap between the customer being told how to remediate and the same endpoint being reported again. 🔍 The headline is a Monero miner compiled on the victim machine instead of dropped as a binary. Huntress calls that unique in its own casework. It does not say how many hosts, which sector, which MagicINFO version, whether the server faced the internet, or who is behind it. It makes no claim about the UK. ⚖️ The useful part is the trail: repeated remote tool downloads, a new admin account, protection switched off and compilers on a signage server all appeared before the miner ran. "Digital signage" sounds like a marketing tool. It is a server on the network, and an attacker's AnyDesk looks like part of the IT toolkit. 🔑 If the server behind your screens began downloading a remote access tool tonight, who would be told, and by when? Full briefing: https://www.pk-sharma.com/briefing/samsung-magicinfo-cve-2025-4632-miner-compiled-on-host #Samsung #MagicINFO #DigitalSignage #Huntress #Cryptominer #AnyDesk #RMM #KEV #PatchManagement #InfoSec #CyberSecurity #CISO #SecOps #UKTech

    0000091
    194 followersView on X
  • SecureChap@SecureChap

    Samsung MagicINFO CVE-2025-4632 was exploited when attackers dropped AnyDesk, disabled Defender via sc config, then compiled a miner on the host with gcc -o miner miner.c. Tracebit Context Bombs plant indirect prompt injection into AWS Secrets Manager canary values. Conversation delimiters like <|endoftext|> halt abliterated model actions before they reach prod pipelines. Zero Salarium uses named-pipe injection, calling WriteFile() on the target's stdin handle instead of WriteProcessMemory or VirtualAllocEx to stay under EDR. YesWeHack cache key injection concatenates attacker fragments with no separators, enabling collisions that poison entries or store XSS payloads. Watch for unexpected WriteFile calls to \.\pipe\ targets from non-standard parents and enforce strict key canonicalization before any cache lookup.

    00000136
    175 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    A new attack chain shows Samsung MagicINFO’s CVE-2025-4632 being exploited to build a cryptominer inside victim Windows machines. Remote access tools, disabled Defender, custom miner compilation & Monero mining via an exposed service. Patch MagicINFO, watch for compiler activity, and lock down admin access. #Samsung #Security #Cryptomining #Infosec #CVE2025-4632 #ThreatIntel #Samsung #Security #Cryptomining #MagicINFO #Monero #CVE2025-4632 https://thedailytechfeed.com/exploit-in-samsung-magicinfo-enabled-cryptomining-on-windows-systems/

    Post summary

    The tweet reports an active attack chain exploiting CVE-2025-4632 to deploy cryptominers on Windows machines via remote access tools, while explicitly advising users to patch MagicINFO.

    00000103
    768 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Huntress found an intrusion via Samsung MagicINFO CVE-2025-4632, followed by repeated AnyDesk installs, Defender tampering, and a SilentXMRMiner-based Monero miner compiled on the endpoint and tied to C3Pool. #MagicINFO #AnyDesk #C3Pool https://www.hendryadrian.com/the-not-so-silent-miner-threat-actor-compiles-cryptominer-on-the-endpoint/

    Post summary

    Huntress observed an intrusion exploiting CVE-2025-4632 in Samsung MagicINFO, leading to further malicious activity including AnyDesk installations and a Monero miner. The report does not detail the vulnerability itself or mention any available patches.

    00000396
    4.9K followersView on X
  • @pedri77@pedri77
    Patch

    Samsung has released software updates to address a critical security flaw in MagicINFO 9 Server that has been actively exploited in the wild. The vulnerability, tracked as CVE-2025-4632 (CVSS score: 9.8), has been descr... https://f.mtr.cool/acouvswjzu

    Post summary

    Samsung released a patch for the high‑severity CVE-2025-4632 affecting MagicINFO 9 Server, which is already being exploited in the wild.

    00000957
    2.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 #Samsung MagicINFO 9 Server, Path Traversal, #CVE-2025-4632 (Critical) https://dailycve.com/samsung-magicinfo-9-server-path-traversal-cve-2025-4632-critical-2/

    Post summary

    The post announces a critical path traversal vulnerability (CVE‑2025‑4632) in Samsung MagicINFO 9 Server, but does not provide details on exploits, patches, or real‑world attacks.

    00000251
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsungmagicinfo_9_server---

Explore more