CVE-2024-24722: 12dsynergy
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.
Affected products
- 12dsynergy 12dsynergy: before 4.3.10.192 (fixed in 4.3.10.192); from 5.1.1.58, before 5.1.5.221 (fixed in 5.1.5.221); from 5.1.6.210, before 5.1.6.235 (fixed in 5.1.6.235)
- 12dsynergy File Replication Server: before 4.3.10.192 (fixed in 4.3.10.192); from 5.1.1.58, before 5.1.5.221 (fixed in 5.1.5.221); from 5.1.6.210, before 5.1.6.235 (fixed in 5.1.6.235)
Published 2024-02-19. Last modified 2026-06-17.