CVE-2023-0012

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:sap:host_agent:7.21:*:*:*:*:*:*:*
cpe:2.3:a:sap:host_agent:7.22:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:36

Type Values Removed Values Added
Summary
  • (es) En SAP Host Agent (Windows), versiones 7.21, 7.22, un atacante que obtenga membresía local en SAP_LocalAdmin podría reemplazar archivos ejecutables con un archivo malicioso que se iniciará con una cuenta privilegiada. Tenga en cuenta que, de forma predeterminada, a todos los usuarios miembros de SAP_LocaAdmin se les niega la capacidad de iniciar sesión localmente por política de seguridad, por lo que esto solo puede ocurrir si el sistema ya se ha visto comprometido.
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 6.4
References () https://launchpad.support.sap.com/#/notes/3276120 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/3276120 - Permissions Required, Vendor Advisory
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

Information

Published : 2023-01-10 03:15

Updated : 2024-11-21 07:36


NVD link : CVE-2023-0012

Mitre link : CVE-2023-0012

CVE.ORG link : CVE-2023-0012


JSON object : View

Products Affected

sap

  • host_agent

microsoft

  • windows
CWE
CWE-284

Improper Access Control