Executive brief
Synology BeeDrive for desktop is a backup and file synchronization application for personal storage devices. A security flaw in how the application loads its internal OpenSSL components allows a local user on the computer to run unauthorized code. If exploited, this could lead to a full system compromise, data theft, or persistent access by an attacker who already has limited access to the machine.
Technical details
An uncontrolled search path element (CWE-427) vulnerability exists in the OpenSSL DLL component of Synology BeeDrive for desktop. The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs), which can be exploited via DLL hijacking. A local attacker with low privileges can place a malicious DLL in a directory searched by the application to execute arbitrary code with the privileges of the BeeDrive process. This vulnerability is resolved in BeeDrive for desktop version 1.3.2-13814 and later. No user interaction is required for exploitation beyond the initial placement of the malicious file.
Affected products
- Synology BeeDrive for desktop before 1.3.2-13814
Timeline
- 2024-11-26: advisory: Initial public release of Synology advisory
- 2024-11-26: patched: Fixed in version 1.3.2-13814
- 2026-05-27: disclosed: Detailed vulnerability information disclosed and CVE published