// For flags

CVE-2017-16690

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possible that SAPSetup / NwSapSetup.exe loads system DLLs like DWMAPI.dll (located in your Syswow64 / System32 folder) from the folder the executable is in and not from the system location. The desired behavior is that system dlls are only loaded from the system folders. If a dll with the same name as the system dll is located in the same folder as the executable, this dll is loaded and code is executed.

Es posible un ataque de precarga de DLL malicioso en NwSapSetup y en el programa autoextraíble de instalación para SAP Plant Connectivity 2.3 y 15.0. Es posible que SAPSetup/NwSapSetup.exe cargue DLL del sistema como DWMAPI.dll (ubicado en la carpeta Syswow64/System32) desde la carpeta en la que se encuentra el ejecutable en lugar de desde la ubicación del sistema. El comportamiento deseable es que los dll del sistema solo se carguen desde las carpetas del sistema. Si un dll con el mismo nombre que el dll del sistema está ubicado en la misma carpeta que el ejecutable, se carga este dll y se ejecuta código.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-09 CVE Reserved
  • 2017-12-12 CVE Published
  • 2023-05-05 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-426: Untrusted Search Path
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Plant Connectivity
Search vendor "Sap" for product "Plant Connectivity"
2.3
Search vendor "Sap" for product "Plant Connectivity" and version "2.3"
-
Affected
Sap
Search vendor "Sap"
Plant Connectivity
Search vendor "Sap" for product "Plant Connectivity"
15.0
Search vendor "Sap" for product "Plant Connectivity" and version "15.0"
-
Affected