Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 00:45:00 +0000

Type Values Removed Values Added
Description Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server.
Title DLL Hijacking vulnerability in SAPSetup
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-01-14T15:03:14.425Z

Reserved: 2024-12-11T05:05:12.090Z

Link: CVE-2025-0069

cve-icon Vulnrichment

Updated: 2025-01-14T15:03:09.934Z

cve-icon NVD

Status : Received

Published: 2025-01-14T01:15:17.257

Modified: 2025-01-14T01:15:17.257

Link: CVE-2025-0069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.