cbcvebase.
CVE-2007-4475
published 2009-04-01

CVE-2007-4475: Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute…

PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
40.31%
98.5th percentile
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.

Affected

7 ranges
VendorProductVersion rangeFixed in
sapsapgui<= 7.10
sapsapgui
sapsapgui
sapsapgui
sapsapgui
sapsapgui
sapsapgui

Detection & IOCsextracted from sources · hover to see the quote

filenamewebviewer3d.dll
commandSaveViewToSessionFile
otherCLSID: webviewer3d ActiveX control (EAI WebViewer3D)
  • Monitor ActiveX method calls to SaveViewToSessionFile() on webviewer3d.dll with abnormally long string arguments, indicative of stack-based buffer overflow exploitation attempts.
  • A public Metasploit module (sapgui_saveviewtosessionfile.rb) exists for this vulnerability targeting Windows XP SP0-SP3 and Windows Vista with IE 6.0 SP0-SP2 and IE 7; browser-based exploit delivery should be monitored.
  • The exploit uses unescape() shellcode delivery via JavaScript in a browser context; detect large unescape() calls in HTML pages served to clients running SAPgui.
  • The Metasploit module sets EXITFUNC to 'process' and uses a payload space of 1024 bytes with null byte as the only bad character; tune shellcode detection signatures accordingly.
  • ·The vulnerability affects SAPgui versions before 7.10 Patch Level 9 only; patched installations are not vulnerable.
  • ·Doc 2 (Exploit-DB 32879) is unrelated to CVE-2007-4475 and covers SAP MaxDB XSS vulnerabilities; its IOCs should not be attributed to this CVE.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.