QNAP fixes NAS backup software zero-day exploited at Pwn2Own
ID: ed94a40d-842d-5e71-83f0-c0530e3da089
STIX ID: report--ed94a40d-842d-5e71-83f0-c0530e3da089
Feed Name: Bleeping Computer
Threat Score
QNAP released a patch for CVE-2024-50388, a critical OS command injection zero-day in HBS 3 Hybrid Backup Sync 25.1.x that was demonstrated by Viettel Cyber Security at Pwn2Own Ireland 2024 to gain arbitrary command execution and admin privileges; the vendor fixed the issue in version 25.1.1.673 and the advisory reminds users to update, noting historical ransomware activity against QNAP NAS devices that increases risk if the vulnerability were abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
