CVE-2024-4461: Sugarsync

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.

Affected products

  • Sugarsync Sugarsync: before 4.1.3 (fixed in 4.1.3)

Published 2024-05-03. Last modified 2026-06-17.