CVE-2023-32113 HIGH

CVE-2023-32113: Information Disclosure vulnerability in SAP GUI for Windows

Vendor Sap_Se
Product SAP GUI for Windows
Weakness CWE-200 · Info exposure
Published May 9, 2023
Last update January 28, 2025

CVSS base score

7.5/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

Key dates

02Disclosure timeline

May 9, 2023 CVE published
January 28, 2025 Record updated