Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 18 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Syncplify
Syncplify syncplify.me Server! |
|
| Vendors & Products |
Syncplify
Syncplify syncplify.me Server! |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path. Attackers can insert a malicious executable into the service path and execute it with LocalSystem privileges when the service restarts or the system reboots. | |
| Title | Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-18T12:58:40.043Z
Reserved: 2026-05-15T13:33:45.700Z
Link: CVE-2020-37230
Updated: 2026-05-18T12:58:35.869Z
Status : Awaiting Analysis
Published: 2026-05-16T16:16:18.920
Modified: 2026-06-17T03:17:18.913
Link: CVE-2020-37230
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:00:56Z