CVE-2023-32113

HIGH

SAP GUI for Windows < 7.70 - Unauthenticated Exposure of NTLM Authentication Information via Shortcut File

Title source: llm
STIX 2.1

Description

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 51.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (3)
sap/gui_for_windows 7.70 (12 CPE variants)
sap/gui_for_windows 8.0 (2 CPE variants)
sap/gui_for_windows < 7.70
Published May 09, 2023
Tracked Since Feb 18, 2026