ZDI-26-187: (Pwn2Own) Synology DiskStation Manager Netatalk Library Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2022-45188.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-187?
The severity of ZDI-26-187 is considered critical due to its potential for remote code execution without authentication.
How do I fix ZDI-26-187?
To fix ZDI-26-187, update your Synology DiskStation Manager to the latest version provided by Synology.
What systems are affected by ZDI-26-187?
ZDI-26-187 affects installations of Synology DiskStation Manager that use the Netatalk library.
Can ZDI-26-187 be exploited remotely?
Yes, ZDI-26-187 can be exploited remotely as it does not require authentication.
What are the potential consequences of ZDI-26-187?
The potential consequences of ZDI-26-187 include unauthorized remote code execution and complete system compromise.