Security ID : NAS-201912-02

Security Advisory for Unquoted Service Path Vulnerability in QNAP NetBak Replicator


  • Release date : December 2, 2019

  • CVE identifier : CVE-2019-7201

  • Affected products: QNAP NetBak Replicator 4.5.11.816 and earlier

Severity

Low

Status

Resolved


Summary

An unquoted service path vulnerability is reported to affect the service “QVssService” in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges.

We have already fixed this issue in QNAP NetBak Replicator 4.5.12.1108.

Recommendation

To avoid the attack, we recommend updating QNAP NetBak Replicator to the latest version.

Installing and Running the Latest Version of QNAP NetBak Replicator

  1. Go to https://www.qnap.com/go/utilities/essentials
  2. Download the NetBak Replicator installer.
  3. Run the installer.
  4. Select Yes to allow NetBak Replicator to makes changes to your device.
  5. Select a language.
  6. Click OK.
    NetBak Replicator Setup Wizard appears.
  7. Click Next.
  8. Accept the terms of the License Agreement.
  9. Click Next.
  10. Select the components that you want to install.
  11. Click Next.
  12. Specify the installation location.
  13. Click Next.
  14. Configure user privilege settings.
  15. Click Install.
    Windows installs NetBak Replicator.
  16. Click Next.
  17. Click Finish.
    NetBak Replicator is installed.

 

Revision History: V1.0 (December 2, 2019) - Published

사양 선택

      더 보기 적게 보기

      다른 국가/지역 사이트:

      open menu
      back to top