CVE-2022-49039: Synology Drive Client

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to execute arbitrary commands via unspecified vectors.

Affected products

  • Synology Drive Client: before 3.4.0-15721 (fixed in 3.4.0-15721)

Published 2024-09-26. Last modified 2026-06-17.