Junglewise Threat Intelligence

CVE-2022-49042: Synology Hyper Backup Explorer code execution in MinGW DLL component

CVE-2022-49042 · Severity: high · CVSS 7.8 · Published 2026-06-03

Vendors: Synology.

Executive brief

Synology Hyper Backup Explorer, a desktop tool used to browse and retrieve files from Synology backup archives, contains a security flaw in its MinGW DLL component. This vulnerability allows a local user with access to the system to execute unauthorized code, potentially leading to a full system compromise or data theft. Organizations should update the software to version 3.0.1-0156 or later to mitigate this risk.

Technical details

A vulnerability classified as 'Inclusion of Functionality from Untrusted Control Sphere' (CWE-829) exists in the MinGW DLL component of Synology Hyper Backup Explorer prior to version 3.0.1-0156. The flaw allows a local attacker with low privileges to execute arbitrary code on the host system via unspecified vectors, likely involving DLL hijacking or improper library loading paths. Successful exploitation grants the attacker the same permissions as the user running the application, potentially leading to complete loss of confidentiality, integrity, and availability. Synology has addressed this issue in version 3.0.1-0156.

Affected products

  • Synology Hyper Backup Explorer before 3.0.1-0156

Timeline

  • 2026-06-03: advisory: NVD publication date

References