CVE-2020-37100 PUBLISHED

Sync Breeze Enterprise 12.4.18 - Unquoted Service Path

Assigner: VulnCheck
Reserved: 01.02.2026 Published: 03.02.2026 Updated: 03.02.2026

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor SyncBreeze
Product Sync Breeze Enterprise
Versions
  • Version 12.4.18 is affected

Credits

  • boku finder

References

Problem Types

  • Unquoted Search Path or Element CWE