Executive brief
Synology Presto Client is a desktop application used for high-speed file transfers to Synology NAS devices. A security flaw in the Windows installer allows a local attacker to gain unauthorized control over the system by placing a malicious file in the same folder as the installer before it is run. This could lead to the theft of sensitive data, modification of system files, or a complete system crash.
Technical details
An uncontrolled search path element vulnerability (CWE-427) exists in the Synology Presto Client installer for Windows. The vulnerability is triggered when the installer attempts to load DLL dependencies from its current working directory without proper validation. A local attacker with low privileges can exploit this by placing a malicious DLL in the same directory as the installer executable. If a user subsequently runs the installer, the malicious code is executed with the privileges of the installer, potentially allowing for arbitrary file read/write operations or a denial-of-service. This issue is resolved in version 2.1.3-0672.
Affected products
- Synology Presto Client before 2.1.3-0672
Timeline
- 2026-02-24: disclosed
- 2026-02-24: patched: Fixed in version 2.1.3-0672
- 2026-02-24: advisory