An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
https://www.12dsynergy.com/security-statement/ | product |
https://files.12dsynergy.com/downloads/download.aspx | product |
https://help.12dsynergy.com/v1/docs/cve-2024-24722 | vendor advisory |