CVE-2026-24317
DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Productos afectados
SAP_SE · SAP GUI for Windows with active GuiXT¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →