Junglewise Threat Intelligence

CVE-2025-66593: Synology Assistant origin validation error in Windows installer

CVE-2025-66593 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology Assistant is a desktop utility used to manage and set up Synology NAS devices on a local network. A security flaw in the Windows version of this tool could allow a local user to create or overwrite files on the system during the installation process. This could lead to system instability or a denial of service, potentially disrupting business operations on the affected workstation.

Technical details

An origin validation error (CWE-346) exists in the Synology Assistant installer for Windows. The vulnerability occurs during the installation process, where insufficient validation of data origins allows a local attacker to trigger arbitrary file writes. While the content of these files is restricted, the ability to write to arbitrary locations can be leveraged to cause a denial of service or impact system integrity. Exploitation requires local access and user interaction. Synology has addressed this issue in version 7.0.6-50085.

Affected products

  • Synology Assistant before 7.0.6-50085

Timeline

  • 2025-12-08: advisory: Initial public release by Synology
  • 2026-05-27: disclosed: Vulnerability details disclosed and NVD entry published
  • 2025-12-08: patched: Fixed in version 7.0.6-50085

References