CVE-2017-11156: High severity synology download station vulnerability
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11156?
CVE-2017-11156 has a high severity due to its potential for remote code execution.
How do I fix CVE-2017-11156?
To fix CVE-2017-11156, upgrade Synology Download Station to version 3.8.5-3475 or later.
What are the affected versions for CVE-2017-11156?
CVE-2017-11156 affects Synology Download Station versions prior to 3.8.5-3475 and 3.x versions earlier than 3.5-2984.
Can unauthorized users exploit CVE-2017-11156?
CVE-2017-11156 requires authenticated users to exploit the weak permissions for code execution.
What type of vulnerability is CVE-2017-11156?
CVE-2017-11156 is a vulnerability that allows for execution of arbitrary code due to improper file permission settings.