PT-2023-22190 · Sap · Sapsetup

Published

2023-04-11

·

Updated

2023-04-26

·

CVE-2023-29187

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SapSetup version 9.0
Description A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup, resulting in a privilege escalation running code as administrator of the same Windows PC. A successful attack depends on various preconditions beyond the attacker's control.
Recommendations For SapSetup version 9.0, consider restricting access to the SapSetup program to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the SapSetup program for software installation until the issue is resolved.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2023-29187

Affected Products

Sapsetup