PT-2026-24159 · Sap · Sap Gui For Windows
CVE-2026-24317
·
Publicado
2026-03-10
·
Atualizado
2026-03-10
CVSS v3.1
5.0
Média
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP GUI for Windows (affected versions not specified)
Description
SAP GUI for Windows permits the loading of DLL files from arbitrary directories within the application. An unauthenticated attacker could exploit this by convincing a victim to place a malicious DLL in one of these directories. The malicious command is executed in the victim user's context if GuiXT is enabled. This impacts the confidentiality, integrity, and availability of the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Gui For Windows