First published: Fri Aug 18 2017(Updated: )
Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Assistant | <=6.1-15030 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11160 is classified as a high-severity vulnerability due to its potential for local code execution.
To fix CVE-2017-11160, update Synology Assistant to version 6.1-15163 or later.
CVE-2017-11160 is associated with multiple untrusted search path vulnerabilities that permit DLL hijacking.
Users of Synology Assistant prior to version 6.1-15163 on Windows are affected by CVE-2017-11160.
CVE-2017-11160 requires local access to the system for exploitation, making it a local attack vector.