CRITICAL🇵🇱 Wersja polska

CVE-2024-24722

CVSS 9.1v3.1pub. 2024-02-19upd. 2025-04-02

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.

🤖 AI Analysis
How it works

The vulnerability results from improper specification of the path to the Windows service executable without using quotes (unquoted service path, CWE-428). When the path contains spaces and is not enclosed in quotes, the Windows system during service startup may inadvertently execute a different file placed by an attacker in an earlier segment of the path. An attacker who manages to place a malicious executable file in the appropriate location can cause it to be executed in the context of a Windows system service, often with high privileges.

Impact

An attacker can obtain elevated privileges in the operating system, which in practice can lead to privilege escalation and takeover of server control. Both confidentiality and data integrity are at risk.

Mitigation & patch

The software should be updated to version 4.3.10.192, 5.1.5.221, or 5.1.6.235, in which the vendor fixed the vulnerability. Patches and details are available at https://help.12dsynergy.com/v1/docs/cve-2024-24722 and on the vendor's website https://www.12dsynergy.com/security-statement/.

Who is affected

12d Synergy Server and 12d Synergy File Replication Server in all versions preceding 4.3.10.192, 5.1.5.221, and 5.1.6.235.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • 12dsynergy

    APP
    12Dsynergy
    < 4.3.10.1925.1.1.58 – 5.1.5.221 (excl.)5.1.6.210 – 5.1.6.235 (excl.)
  • 12dsynergy File Replication Server

    APP
    12Dsynergy
    < 4.3.10.1925.1.1.58 – 5.1.5.221 (excl.)5.1.6.210 – 5.1.6.235 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References