cve-2025-4679

About this tag
CVE-2025-4679 is a critical security vulnerability discovered in Synology's Active Backup for Microsoft 365 (ABM). Identified by security firm ModZero during a red-team assessment, the flaw stems from improper handling of OAuth credentials during the ABM setup process. This allows threat actors to compromise sensitive Microsoft 365 tenant data without requiring prior authentication to Synology or Microsoft systems. The vulnerability highlights risks in SaaS backup providers and cloud application supply chains, as enterprises increasingly rely on third-party backup solutions. Discussions on WindowsForum cover the technical details, potential impact on global IT security, and lessons for securing cloud backup infrastructure.
  1. Critical Synology Active Backup for Microsoft 365 Vulnerability Exposes Tenant Data

    A significant security vulnerability has been identified in Synology's Active Backup for Microsoft 365 (ABM), potentially exposing sensitive data across all Microsoft 365 tenants utilizing this backup solution. This flaw, designated as CVE-2025-4679, was discovered by the security firm ModZero...
  2. Synology ABM Microsoft 365 Vulnerability Exposes Global SaaS Backup Risks

    A critical vulnerability uncovered in Synology’s Active Backup for Microsoft 365 (ABM) has sparked concern throughout the global IT security community, shedding light on the intertwined risks associated with SaaS backup providers and cloud application supply chains. The flaw, now catalogued as...