Executive brief
Synology Active Backup for Business Agent is a tool used to back up Windows computers to a central Synology server. A security flaw in the software's installer allows a local user to create or overwrite files on the system during the installation process. This could potentially be used to disrupt system operations or interfere with the backup software's configuration.
Technical details
An origin validation error (CWE-346) exists in the Synology Active Backup for Business Agent installer for Windows. The vulnerability occurs during the installation phase, where insufficient validation of file origins allows a local attacker to trigger arbitrary file writes. While the content that can be written is restricted, the flaw can be exploited to overwrite critical system or application files, leading to a loss of integrity or availability. Exploitation requires local access and typically involves user interaction during the installation process. The issue is resolved in version 3.1.0-4967.
Affected products
- Synology Active Backup for Business Agent before 3.1.0-4967
Timeline
- 2025-12-08: advisory: Initial public release of Synology security advisory
- 2026-05-27: disclosed: Vulnerability details and CVE-2025-66592 published
- 2026-05-27: patched: Fix available in version 3.1.0-4967