« Volver al listado

CVE-2023-32113

Estado: ModificadaCrítica (9.3)—

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-32113",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-32113",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-28T19:03:31.530001Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP GUI for Windows",
          "versions": [
            {
              "status": "affected",
              "version": "<= 7.70"
            },
            {
              "status": "affected",
              "version": "7.70 PL0",
              "versionType": "custom",
              "lessThanOrEqual": "7.70 PL11"
            },
            {
              "status": "affected",
              "version": "8.00 PL0",
              "versionType": "custom",
              "lessThanOrEqual": "8.00 PL1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-05-09T02:15:12.873",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/3320467",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3320467",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.\n\n"
    }
  ],
  "lastModified": "2026-06-17T05:58:06.597",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44424F57-EDAC-42EE-8C29-F9AA09301A46",
              "versionEndExcluding": "7.70"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE1286F1-B9A5-4F25-B083-272943D90023"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF605CA1-E860-4185-A358-FE967E0DE408"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D569EBA-CE95-436E-BB48-D2EF55DD9D30"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A81A5609-2ADD-4714-8783-27BC417346D1"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "181183AC-5621-4895-82E1-E91D9DCAB69A"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD057E0A-C836-46ED-ACB3-1C80CECACD60"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AEA7D81-E487-4B85-81FF-338E2C48D282"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4114FB5F-DE93-4C1F-80E2-08ADC51BC2B1"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F65D7775-75DC-4F88-AC76-C4EEC59A2DE4"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02EC1177-F290-4488-B365-F107A7CBBA09"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "532B87F7-19BF-4956-A0A6-4F76755EF1F0"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:patch_level9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "662D074A-F79A-4936-925E-54C7DDC45BB4"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:8.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A69E51CD-C3D1-4B66-94AA-45B2A848912C"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:8.0:patch_level1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E736149-FB18-47E7-B6DA-6459D4AC235D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}