CVE-2022-49042: High severity Synology Hyper Backup Explorer vulnerability
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synology Hyper Backup Explorerto a version that resolves this vulnerability.Fixed in 3.0.1-0156
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49042?
The severity of CVE-2022-49042 is rated as high with a CVSS score of 7.8.
How do I fix CVE-2022-49042?
To fix CVE-2022-49042, upgrade to the latest version of Synology Hyper Backup Explorer, specifically version 3.0.1-0156 or later.
What type of vulnerability is CVE-2022-49042?
CVE-2022-49042 is a vulnerability related to the inclusion of functionality from an untrusted control sphere in the MinGW DLL component.
What can attackers achieve with CVE-2022-49042?
Attackers can exploit CVE-2022-49042 to execute arbitrary code locally.
Which version of Synology Hyper Backup Explorer is affected by CVE-2022-49042?
CVE-2022-49042 affects versions of Synology Hyper Backup Explorer prior to 3.0.1-0156.