CVE-2017-11153
Description
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
In plain language
AI Worth attentionIf you run Synology Photo Station and it’s older than 6.7.3-3432 (or older than 6.3-2967), an attacker on the network can send a specially crafted message to take full administrator control of your server—this is serious for a typical small business.
In Synology Photo Station, an unauthenticated network attacker can exploit a deserialization weakness in synophoto_csPhotoMisc.php (unsafe processing of crafted serialized data) to gain administrator privileges and fully compromise the system.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-11153 and every CVE in our database. Create a free account — no credit card required.
Create Free Account