Sensitive Information Exposure in Synology Active Backup for Microsoft 365
CVE-2025-4679
What is CVE-2025-4679?
A vulnerability in Synology Active Backup for Microsoft 365 permits remote authenticated attackers to gain access to sensitive data through unspecified methods, potentially compromising user privacy and security. This flaw underscores the importance of stringent access controls and prompt security updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Active Backup for Microsoft 365 Unknown
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved