PT-2023-22190 · Sap · Sapsetup

CVE-2023-29187

·

Publicado

2023-04-11

·

Atualizado

2023-04-26

CVSS v3.1

6.7

Média

VetorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SapSetup version 9.0
Description A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup, resulting in a privilege escalation running code as administrator of the same Windows PC. A successful attack depends on various preconditions beyond the attacker's control.
Recommendations For SapSetup version 9.0, consider restricting access to the SapSetup program to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the SapSetup program for software installation until the issue is resolved.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-29187

Produtos afetados

Sapsetup