PT-2017-11775 · Synology · Synology Office
Published
2017-08-14
·
Updated
2019-10-03
·
CVE-2017-11150
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Synology Office versions 2.2.0-1502 through 2.2.1-1506
Description
A command injection issue exists, allowing remote authenticated users to execute arbitrary commands. This is achieved by using shell metacharacters in the crafted file name of RTF documents.
Recommendations
For versions 2.2.0-1502 through 2.2.1-1506, update to a version that contains a fix for this issue.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synology Office