Synology-SA-25:15 ActiveProtect Agent

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the ActiveProtect Agent on Windows to address a vulnerability :
      • CVE-2025-13593 allows local users to write arbitrary files with restricted content.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
ActiveProtect Agent Moderate Upgrade to 1.1.0-0439 or above.

Mitigation

None

Detail

Acknowledgement

Sheikh Rishad (https://x.com/sheikhrishad0)

Revision

Revision Date Description
1 2025-11-24 Initial public release.