Uncontrolled Search Path Element Vulnerability in Synology BeeDrive for Desktop
CVE-2023-52945

7.8HIGH

Key Information:

Vendor

Synology

Vendor
CVE Published:
27 May 2026

What is CVE-2023-52945?

An uncontrolled search path element vulnerability exists in the OpenSSL DLL component of Synology BeeDrive for desktop, allowing local users to execute arbitrary code. This issue affects versions prior to 1.3.2-13814 and poses significant risks if exploited, as it could enable unauthorized commands execution within the system. Users are urged to update to the latest version to mitigate potential threats.

Affected Version(s)

BeeDrive for desktop *

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhao Runzi (赵润梓)
.