DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
| Software | From | Fixed in |
|---|---|---|
| ivanti / desktop_&_server_management | 2022.2 | 2022.2.x |
| ivanti / desktop_&_server_management | 2022.2-su1 | 2022.2-su1.x |
| ivanti / desktop_&_server_management | 2022.2-su2 | 2022.2-su2.x |
| ivanti / desktop_&_server_management | - | 2022.2 |