Vulnerabilities (CVE)

Filtered by vendor Synology Subscribe
Filtered by product Assistant
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-66593 1 Synology 1 Assistant 2026-06-02 N/A 6.1 MEDIUM
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
CVE-2017-11160 1 Synology 1 Assistant 2026-05-13 4.6 MEDIUM 7.8 HIGH
Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.