Security researchers found a serious zero-click bug in Synology’s Photos app

If you own a Synology NAS drive, you’ll want to update your device as soon as possible. As first reported by Wired, a group of Dutch security researchers recently identified a zero-click vulnerability within the Synology Photos app. For the uninitiated, such bugs allow hackers to compromise a system without a user needing to click something first. To make matters worse, the app comes pre-installed and enabled by default on Synology’s consumer line of Bee network storage devices. It’s also a popular download among those who use the company’s DiskStation systems.

Midnight Blue, the cybersecurity firm that discovered the vulnerability, estimates that millions of Synology users may be at risk. Although the company released a security patch to address the bug, its NAS devices do not automatically download updates. “It’s not trivial to find [the vulnerability] on your own, independently,” Carlo Meijer, one of the researchers, told Wired. “But it is pretty easy to figure out and connect the dots when the patch is actually released, and you reverse-engineer the patch.”

According to Midnight Blue, the zero-click is found in a part of the Synology Photos app that does not require authentication. As a result, attackers can exploit the bug directly over the internet and without needing to bypass a gateway first. They can then gain root access and install malicious code on the compromised device. At that point, there’s not much a malicious individual couldn’t do, with the firm noting it would even be possible to turn the infected device into a botnet. The possibility a ransomware gang could target Synology devices isn’t just theoretical either. Earlier this year, DiskStation users reported that they were the target of a ransomware attack.

This article originally appeared on Engadget at https://www.engadget.com/computing/security-researchers-found-a-serious-zero-click-bug-in-synologys-photos-app-145147159.html?src=rss

HOT news

Related posts

Latest posts

The ‘Bear Market Sign’: This Bitcoin Indicator Simply Flashed Pink After 3 Years

Bitcoin stabilized above $66,000 on Friday, although the asset has fallen about 30% over the previous month. In keeping with evaluation by Alphractal, Bitcoin’s...

A Neva prequel is arriving subsequent week

At Sony's State of Play yesterday, developer Nomada Studio revealed a DLC prequel to its beautiful and award-winning puzzle platformer Neva. Entitled merely Neva:...

Greatest Crypto to Purchase Now February 12 – XRP, Dogecoin, Solana

Crypto believers are enjoying the lengthy sport, making downturns like this one one of the best time to purchase extra.As Bitcoin ($BTC) struggles under...

Crypto Value Evaluation February-13: ETH, XRP, ADA, BNB, and HYPE

This Friday, we study Ethereum, Ripple, Cardano, Binance Coin, and Hyperliquid in better element. Ethereum (ETH) Ethereum closed the week up 2%, however the...

Ethereum Value Prediction: Is the Backside In for ETH? $1.8K Assist Holds Key to Restoration

Following the aggressive sell-off towards the $1.8K demand area, Ethereum stabilised and produced a corrective rebound. Nevertheless, this restoration lacks robust momentum and is...

Want to stay up to date with the latest news?

We would love to hear from you! Please fill in your details and we will stay in touch. It's that simple!