CVE-2020-37100
Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.
- Affected products
- Syncbreeze Enterprise, Syncbreeze
- Flexense Syncbreeze
- = 12.4.18
- Fix
- Available
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (9th percentile)
- Weakness
- CWE-428
- NVD status
- Analyzed
- Published
- 2026-02-03
CVE-2020-37100 at NVD
No indexed exploits for CVE-2020-37100 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-37100 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.