DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Desktop_&_server_management | Ivanti | * | 2022.2 (excluding) |
Desktop_&_server_management | Ivanti | 2022.2 (including) | 2022.2 (including) |
Desktop_&_server_management | Ivanti | 2022.2-su1 (including) | 2022.2-su1 (including) |
Desktop_&_server_management | Ivanti | 2022.2-su2 (including) | 2022.2-su2 (including) |