CVE-2022-49039: Medium severity synology drive client vulnerability
Published Sep 26, 2024
·Updated
Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to execute arbitrary commands via unspecified vectors.
Affected Software
1 affected component
Synology Drive Client Desktop<3.4.0-15721
Event History
Sep 26, 2024
CVE Published
via MITRE·03:33 AM
Data Sourced
via MITRE·03:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-49039?
CVE-2022-49039 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
2
How do I fix CVE-2022-49039?
To mitigate CVE-2022-49039, update Synology Drive Client to version 3.4.0-15721 or later.
3
Who is affected by CVE-2022-49039?
CVE-2022-49039 affects local users with administrator privileges on Synology Drive Client versions prior to 3.4.0-15721.
4
What type of vulnerability is CVE-2022-49039?
CVE-2022-49039 is an out-of-bounds write vulnerability related to backup task management in Synology Drive Client.
5
What can attackers do with CVE-2022-49039?
Attackers exploiting CVE-2022-49039 can execute arbitrary commands on affected systems.