PT-2024-6708 · Synology · Synology Drive Client
Zhao Runzi
·
Published
2024-01-30
·
Updated
2024-10-08
·
CVE-2022-49038
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Synology Drive Client versions prior to 3.3.0-15082
Description:
The issue is related to the inclusion of functionality from an untrusted control sphere in the OpenSSL DLL component. This allows local users to execute arbitrary code via unspecified vectors. The vulnerability is associated with the manipulation of unknown input data, which can be exploited by an attacker to execute arbitrary code.
Recommendations:
For versions prior to 3.3.0-15082, update to version 3.3.0-15082 or later to resolve the issue. As a temporary workaround, consider restricting access to the OpenSSL DLL component until a patch is applied. Avoid using the Synology Drive Client with untrusted input data to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synology Drive Client