Executive brief
Synology Assistant is a desktop utility used to manage and set up Synology NAS devices on a local network. A security flaw in the Windows version of this tool could allow a local user to create or overwrite files on the system during the installation process. This could lead to system instability or a denial of service, potentially disrupting business operations on the affected workstation.
Technical details
An origin validation error (CWE-346) exists in the Synology Assistant installer for Windows. The vulnerability occurs during the installation process, where insufficient validation of data origins allows a local attacker to trigger arbitrary file writes. While the content of these files is restricted, the ability to write to arbitrary locations can be leveraged to cause a denial of service or impact system integrity. Exploitation requires local access and user interaction. Synology has addressed this issue in version 7.0.6-50085.
Affected products
- Synology Assistant before 7.0.6-50085
Timeline
- 2025-12-08: advisory: Initial public release by Synology
- 2026-05-27: disclosed: Vulnerability details disclosed and NVD entry published
- 2025-12-08: patched: Fixed in version 7.0.6-50085