PT-2026-41430 · Syncplify · Syncplify.Me Server!

Julio Aviña

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2020-37230

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path. Attackers can insert a malicious executable into the service path and execute it with LocalSystem privileges when the service restarts or the system reboots.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-37230

Affected Products

Syncplify.Me Server!