SAP AG SAPgui 'mdrmsap.dll' ActiveX Control Remote Code Execution Vulnerability
BID:32186
Info
SAP AG SAPgui 'mdrmsap.dll' ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 32186 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4387 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2008 12:00AM |
| Updated: | Nov 11 2008 01:34AM |
| Credit: | Will Dormann of the CERT/CC |
| Vulnerable: |
SAP AG SAPgui 0 |
| Not Vulnerable: | |
Discussion
SAP AG SAPgui 'mdrmsap.dll' ActiveX Control Remote Code Execution Vulnerability
SAP AG SAPgui is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
SAP AG SAPgui is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
SAP AG SAPgui 'mdrmsap.dll' ActiveX Control Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP AG SAPgui 'mdrmsap.dll' ActiveX Control Remote Code Execution Vulnerability
Solution:
The vendor has released a new version of the application. Please refer to SAP note 1142431 for more information.
Solution:
The vendor has released a new version of the application. Please refer to SAP note 1142431 for more information.
References
SAP AG SAPgui 'mdrmsap.dll' ActiveX Control Remote Code Execution Vulnerability
References:
References:
- SAP Homepage (SAP)
- Vulnerability Note VU#277313 (US-CERT)