CVE-2017-11150: Synology Office
High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents.
Affected products
- Synology Office: version 2.2.0-1502 only; version 2.2.1-1506 only
Published 2017-08-14. Last modified 2026-06-17.