ZDI-21-592: QNAP NAS Malware Remover Command Injection Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of QNAP NAS. Authentication is required to exploit this vulnerability. The specific flaw exists within the Malware Remover application. A crafted TAR file in the file system can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the admin user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-592?
The severity of ZDI-21-592 is considered high due to the potential for local privilege escalation.
How do I fix ZDI-21-592?
To fix ZDI-21-592, ensure that the Malware Remover application on your QNAP NAS is updated to the latest version provided by QNAP.
What systems are affected by ZDI-21-592?
ZDI-21-592 affects QNAP NAS installations that have the Malware Remover application present.
Is authentication required to exploit ZDI-21-592?
Yes, authentication is required for a local attacker to exploit the ZDI-21-592 vulnerability.
What type of attack is associated with ZDI-21-592?
ZDI-21-592 is associated with local privilege escalation attacks that exploit vulnerabilities within the Malware Remover application.