### [CVE-2017-11153](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11153) ![](https://img.shields.io/static/v1?label=Product&message=Synology%20Photo%20Station&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Deserialization%20of%20Untrusted%20Data%20(CWE-502)&color=brighgreen) ### Description Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload. ### POC #### Reference - https://www.exploit-db.com/exploits/42434/ #### Github No PoCs found on GitHub currently.