SAP GUI NTLM Authentication Vulnerability

SAP GUI NTLM Authentication Vulnerability

On May 15, 2023 a vulnerability regarding SAP GUI for Windows - version 7.70, 8.0 has been released.

SAP GUI NTLM Authentication Vulnerability

SAP GUI for Windows version 7.70, 8.0 allows an unauthorized attacker to gain NTLM authentication information of a potential victim by tricking it into clicking a prepared shortcut file. Attacker may be able to read and modify potentially sensitive information after successful exploitation depending on the authorizations of the victim. (CVE-2023-32113)

Affected Systems

  • cpe:2.3:a:sap:gui_for_windows:7.70:-:*:*:*:*:*:*
  • cpe:2.3:a:sap:gui_for_windows:8.0:-:*:*:*:*:*:*

IoC’s

-

Recommended Solution(s)

-

Mitigations

-

CVE / CWE

CVE-2023-32113

Related Website(s)

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.