Synology Security Advisory SA-25:15 ActiveProtect Agent
Security update for ActiveProtect Agent on Windows to address vulnerability
This is a Press Release edited by StorageNewsletter.com on November 28, 2025 at 2:00 pmSynology, Inc. had published a security advisory on resolved vulnerability in ActiveProtect Agent on Windows.
Publish Time: 2025-11-25 09:47:04 UTC+8
Last Updated: 2025-11-25 09:47:25 UTC+8
Severity: Moderate
Status: Resolved
Abstract:
Synology has released a security update for the ActiveProtect Agent on Windows to address a vulnerability :
-
-
-
CVE-2025-13593 allows local users to write arbitrary files with restricted content.
-
-
Refer to the ‘Affected Products’ table for the corresponding updates.
Affected Products:
|
Product |
Severity |
Fixed Release Availability |
|---|---|---|
|
ActiveProtect Agent |
Moderate |
Upgrade to 1.1.0-0439 or above. |
Mitigation: None
Detail:
- CVE-2025-13593
- Severity: Moderate
- CVSS3 Base Score: 6.1
- CVSS3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
- CWE-346: Origin Validation Error
- ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Acknowledgement:
Sheikh Rishad (https://x.com/sheikhrishad0)
Revision:
|
Revision |
Date |
Description |
|---|---|---|
|
1 |
2025-11-24 |
Initial public release. |










