Junglewise Threat Intelligence

CVE-2025-66592: Synology Active Backup for Business Agent arbitrary file write during installation

CVE-2025-66592 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology Active Backup for Business Agent is a tool used to back up Windows computers to a central Synology server. A security flaw in the software's installer allows a local user to create or overwrite files on the system during the installation process. This could potentially be used to disrupt system operations or interfere with the backup software's configuration.

Technical details

An origin validation error (CWE-346) exists in the Synology Active Backup for Business Agent installer for Windows. The vulnerability occurs during the installation phase, where insufficient validation of file origins allows a local attacker to trigger arbitrary file writes. While the content that can be written is restricted, the flaw can be exploited to overwrite critical system or application files, leading to a loss of integrity or availability. Exploitation requires local access and typically involves user interaction during the installation process. The issue is resolved in version 3.1.0-4967.

Affected products

  • Synology Active Backup for Business Agent before 3.1.0-4967

Timeline

  • 2025-12-08: advisory: Initial public release of Synology security advisory
  • 2026-05-27: disclosed: Vulnerability details and CVE-2025-66592 published
  • 2026-05-27: patched: Fix available in version 3.1.0-4967

References