First published: Thu Aug 24 2017(Updated: )
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DNS Server | <=2.2.0-3032 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12074 has a high severity rating as it allows remote authenticated attackers to write arbitrary files on the system.
To fix CVE-2017-12074, upgrade Synology DNS Server to version 2.2.1-3043 or later.
CVE-2017-12074 affects Synology DNS Server versions prior to 2.2.1-3042.
CVE-2017-12074 is a directory traversal vulnerability that can be exploited by authenticated attackers.
Yes, CVE-2017-12074 can be exploited remotely by authenticated attackers.