CVE-2024-4464: Synology Media Server

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.

Affected products

  • Synology Media Server: before 1.4-2680 (fixed in 1.4-2680); from 2.0.0-11050, before 2.0.5-3152 (fixed in 2.0.5-3152); from 2.2.0-3324, before 2.2.0-3325 (fixed in 2.2.0-3325)

Published 2024-12-18. Last modified 2026-06-17.