Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwc5-f9r2-52h9

Опубликовано: 10 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.

EPSS

Процентиль: 7%
0.00176
Низкий

5 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 5
nvd
6 месяцев назад

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.

CVSS3: 5
fstec
6 месяцев назад

Уязвимость графического интерфейса пользователя SAP GUI для Windows, связанная с недостатками механизма вызовов системных библиотек, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 7%
0.00176
Низкий

5 Medium

CVSS3

Дефекты

CWE-427