Junglewise Threat Intelligence

CVE-2020-37230: Syncplify.me Server! unquoted service path in SMWebRestServicev5

CVE-2020-37230 · Severity: high · CVSS 7.8 · Published 2026-05-16

Executive brief

Syncplify.me Server! is a secure file transfer platform used by organizations to manage sensitive data. A vulnerability in the software's service configuration allows a local user with low-level access to gain full administrative control over the server. This could lead to unauthorized access to all stored files, service disruption, or the ability to use the server as a foothold for further attacks on the corporate network.

Technical details

The SMWebRestServicev5 service in Syncplify.me Server! versions up to 5.0.37 is configured with an unquoted executable path containing spaces (C:\Program Files\Syncplify\Syncplify.me Server!\SMWebRestSvc.exe). Due to how Windows resolves service paths, a local attacker with write permissions to the 'C:\' or 'C:\Program Files\' directories can place a malicious executable (e.g., 'Program.exe') that will be executed instead of the legitimate service. This occurs when the service restarts or the system reboots. Because the service runs as LocalSystem, the attacker's code will execute with the highest possible privileges on the Windows host.

Affected products

  • Syncplify Syncplify.me Server! <= 5.0.37

Timeline

  • 2020-11-08: disclosed: Vulnerability discovered and exploit developed by Julio Aviña
  • 2020-11-09: other: Exploit published to Exploit-DB
  • 2026-05-16: advisory: CVE published and NVD record created

References