Junglewise Threat Intelligence

CVE-2023-52945: Synology BeeDrive for desktop uncontrolled search path in OpenSSL DLL

CVE-2023-52945 · Severity: high · CVSS 7.8 · Published 2026-05-27

Technologies: Synology BeeDrive. Vendors: Synology.

Executive brief

Synology BeeDrive for desktop is a backup and file synchronization application for personal storage devices. A security flaw in how the application loads its internal OpenSSL components allows a local user on the computer to run unauthorized code. If exploited, this could lead to a full system compromise, data theft, or persistent access by an attacker who already has limited access to the machine.

Technical details

An uncontrolled search path element (CWE-427) vulnerability exists in the OpenSSL DLL component of Synology BeeDrive for desktop. The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs), which can be exploited via DLL hijacking. A local attacker with low privileges can place a malicious DLL in a directory searched by the application to execute arbitrary code with the privileges of the BeeDrive process. This vulnerability is resolved in BeeDrive for desktop version 1.3.2-13814 and later. No user interaction is required for exploitation beyond the initial placement of the malicious file.

Affected products

  • Synology BeeDrive for desktop before 1.3.2-13814

Timeline

  • 2024-11-26: advisory: Initial public release of Synology advisory
  • 2024-11-26: patched: Fixed in version 1.3.2-13814
  • 2026-05-27: disclosed: Detailed vulnerability information disclosed and CVE published

References

Related threats