SAP GUI DLL Loading Arbitrary Code Execution Vulnerability
BID:46857
Info
SAP GUI DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 46857 |
| Class: | Design Error |
| CVE: |
CVE-2011-5154 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2011 12:00AM |
| Updated: | Sep 06 2012 10:40PM |
| Credit: | Digital Security Research Group |
| Vulnerable: |
SAP SAP GUI for Windows 7.00 patch level 6 SAP SAP GUI for Windows 6.40 patch level 30 SAP SAP GUI 7.2 SAP SAP GUI 7.10 PL SAP SAP GUI 7.10 SAP SAP GUI 7.0 SAP SAP GUI 6.40 Patch 29 SAP SAP GUI 6.4 SAP AG SAPgui 7.10 Patch Level 9 SAP AG SAPgui 7.10 Patch Level 8 SAP AG SAPgui 7.10 Patch Level 5 SAP AG SAPgui 6.40 Patch Level 29 SAP AG SAPgui 6.4 SAP AG SAPgui 0 |
| Not Vulnerable: | |
Discussion
SAP GUI DLL Loading Arbitrary Code Execution Vulnerability
SAP GUI is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
SAP GUI versions 6.4 through 7.2 are vulnerable; other versions may also be affected.
SAP GUI is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
SAP GUI versions 6.4 through 7.2 are vulnerable; other versions may also be affected.
Exploit / POC
SAP GUI DLL Loading Arbitrary Code Execution Vulnerability
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
SAP GUI DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
SAP GUI DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- [DSECRG-11-014] SAP GUI (sapgui) - DLL hijacking (Digital Security Research Group)
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- SAP GUI Family (SAP)
- Microsoft Security Advisory (2269637) (Microsoft)
- SAP Note 1511179 (SAP)