Vulnerabilities (CVE)

Filtered by vendor Synology Subscribe
Filtered by product Assistant
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-4793 2 Microsoft, Synology 2 Windows, Assistant 2026-08-21 N/A 7.3 HIGH
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
CVE-2025-66593 1 Synology 1 Assistant 2026-06-17 N/A 6.1 MEDIUM
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
CVE-2017-11160 1 Synology 1 Assistant 2026-06-17 4.6 MEDIUM 7.8 HIGH
Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.