CVE-2023-32113
HIGHSAP GUI for Windows < 7.70 - Unauthenticated Exposure of NTLM Authentication Information via Shortcut File
Title source: llmDescription
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3320467
Scores
CVSS v3
7.5
EPSS
0.0028
EPSS Percentile
51.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-200
Status
published
Products (3)
sap/gui_for_windows
7.70 (12 CPE variants)
sap/gui_for_windows
8.0 (2 CPE variants)
sap/gui_for_windows
< 7.70
Published
May 09, 2023
Tracked Since
Feb 18, 2026