Arbitrary Code Execution Vulnerability in Synology Active Backup for Business Recovery Media Creator
CVE-2022-49036

7.8HIGH

What is CVE-2022-49036?

An inclusion of functionality from an untrusted control sphere in the OpenSSL configuration for Synology's Active Backup for Business Recovery Media Creator prior to version 2.5.0-2081 permits local users to execute arbitrary code through unspecified means. This vulnerability could allow attackers to compromise system integrity and perform unauthorized operations.

Affected Version(s)

Synology Active Backup for Business Recovery Media Creator *

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhao Runzi (赵润梓)
.