First published: Wed Aug 23 2017(Updated: )
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station Uploader | <=1.4.1-083 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11159 is considered a high severity vulnerability due to its potential for local attackers to execute arbitrary code.
To fix CVE-2017-11159, update Synology Photo Station Uploader to version 1.4.2-084 or later.
Users of Synology Photo Station Uploader versions prior to 1.4.2-084 on Windows are affected by CVE-2017-11159.
CVE-2017-11159 is associated with DLL hijacking attacks which can lead to arbitrary code execution.
No, CVE-2017-11159 requires local access to exploit the vulnerability.