PT-2023-22190 · Sap · Sapsetup
CVE-2023-29187
·
Publicado
2023-04-11
·
Atualizado
2023-04-26
CVSS v3.1
6.7
Média
| Vetor | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SapSetup version 9.0
Description
A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup, resulting in a privilege escalation running code as administrator of the same Windows PC. A successful attack depends on various preconditions beyond the attacker's control.
Recommendations
For SapSetup version 9.0, consider restricting access to the SapSetup program to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the SapSetup program for software installation until the issue is resolved.
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sapsetup