This allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file.
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5154
Vulnerable Systems:
* SAP GUI 7.2 and prior
Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2.
Vendor Status:
Vendor as issued an updated vulnerability.
Patch Availability:
https://service.sap.com/sap/support/notes/1511179
CVE Information:
CVE-2011-5154
Disclosure Timeline:
Publish Date : 2012-09-06
Last Update Date : 2012-09-06
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by