CVE Published: 31/08/2017 |
CVE Updated: 17/09/2024 |
CVE Year: 2017 Source: synology |
Vendor: Synology |
Product: Cloud Station Drive Status : PUBLISHED
CVE-2017-11158 Description
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.