Synology-SA-25:17 Synology Assistant

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the Assistant on Windows to address a vulnerability :
      • CVE-2025-66593 allows local users to write arbitrary files with restricted content.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Synology Assistant Moderate Upgrade to 7.0.6-50085 or above.

Mitigation

None

Detail

Acknowledgement

Sheikh Rishad (https://x.com/sheikhrishad0)

Revision

Revision Date Description
1 2025-12-08 Initial public release.