CVE-2007-3606

SAP EnjoySAP - Heap-Based Buffer Overflow via LaunchGui Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3606. PoCs published by Mark Litchfield.

AI-analyzed exploit summary This exploit demonstrates a heap overflow vulnerability in the EnjoySAP (SAP GUI for Windows) ActiveX control 'rfcguisink.rfcguisink.1' via the 'LaunchGui' function. It triggers the vulnerability by passing an overly long string argument, potentially leading to remote code execution.

Description

Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mark Litchfield · htmldoswindows
https://www.exploit-db.com/exploits/4149

This exploit demonstrates a heap overflow vulnerability in the EnjoySAP (SAP GUI for Windows) ActiveX control 'rfcguisink.rfcguisink.1' via the 'LaunchGui' function. It triggers the vulnerability by passing an overly long string argument, potentially leading to remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: SAP GUI for Windows (EnjoySAP) - All ASCII Versions
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a malicious HTML file · ActiveX controls must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24777
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37689
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24776
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25959
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4149
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2449
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35268

Scores

EPSS 0.0765
EPSS Percentile 93.8%

Details

Status published
Products (1)
sap/enjoysap
Published Jul 06, 2007
Tracked Since Feb 18, 2026