First published: Mon Jul 31 2017(Updated: )
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | <=6.7.2-3429 | |
Synology Photo Station | =6.3-2967 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11153 is classified as a critical vulnerability due to its potential to allow remote attackers to gain administrator privileges.
To fix CVE-2017-11153, upgrade Synology Photo Station to version 6.7.3-3432 or later, or 6.3-2968 or later.
CVE-2017-11153 affects Synology Photo Station versions prior to 6.7.3-3432 and 6.3-2967.
CVE-2017-11153 is a deserialization vulnerability that can be exploited through crafted serialized payloads.
The impact of CVE-2017-11153 can lead to unauthorized access, allowing attackers to perform actions with administrator privileges.