Impact
SAProuter on Microsoft Windows is vulnerable to DLL hijacking. An unauthenticated attacker can place a malicious DLL in an untrusted location that SAProuter will load, allowing arbitrary code execution and giving the attacker full control over the affected system. This would compromise the confidentiality, integrity, and availability of the host.
Affected Systems
All deployments of SAProuter on Microsoft Windows are affected, as the flaw exists in any installed instance; specific version information has not been disclosed by the CNA at this time.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability, while the EPSS score of <1% shows a very low but nonzero likelihood of exploitation. The issue is not cataloged in CISA KEV. Because the attack does not require authentication or elevated privileges, the compromise can occur as soon as an attacker can write a DLL to a directory that SAProuter scans, making it a serious risk for exposed installations.
OpenCVE Enrichment