ZDI-26-268: Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Samsung MagicINFO 9 Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-25203.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-268?
The severity of ZDI-26-268 is classified as critical due to the potential for local privilege escalation.
How do I fix ZDI-26-268?
To fix ZDI-26-268, ensure that the Samsung MagicINFO 9 Server is updated to a version that addresses this vulnerability.
Who is affected by ZDI-26-268?
Users and organizations running affected installations of Samsung MagicINFO 9 Server are impacted by ZDI-26-268.
What type of vulnerability is ZDI-26-268?
ZDI-26-268 is a local privilege escalation vulnerability that allows attackers to gain elevated privileges.
Can ZDI-26-268 be exploited remotely?
No, ZDI-26-268 requires local access to the system to execute the initial low-privileged code for exploitation.