First published: Mon Dec 11 2017(Updated: )
A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Qsync | <=4.2.2.0724 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13070 is considered a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2017-13070, update QNAP Qsync to version 4.3.0 or later.
CVE-2017-13070 affects QNAP Qsync versions 4.2.2.0724 and earlier.
CVE-2017-13070 is a DLL Hijacking vulnerability that allows for arbitrary code execution.
Yes, CVE-2017-13070 can be exploited remotely by attackers to execute arbitrary code on affected systems.