CVE-2023-0012
published 2023-01-10CVE-2023-0012: In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.20%
9.6th percentile
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | host_agent | — | — |
| sap | host_agent | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xh7r-hcfv-6wpx: In SAP Host Agent (Windows) - versions 7
ghsa_unreviewed·2023-01-10
CVE-2023-0012 [MEDIUM] CWE-284 GHSA-xh7r-hcfv-6wpx: In SAP Host Agent (Windows) - versions 7
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.
CISA
Vmware Aria Operations for Networks Command Injection Vulnerability
cisa·2023-06-22·CVSS 9.8
CVE-2023-20887 [CRITICAL] CWE-77 Vmware Aria Operations for Networks Command Injection Vulnerability
Vulnerability: Vmware Aria Operations for Networks Command Injection Vulnerability
Affected: VMware Aria Operations for Networks
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://www.vmware.com/security/advisories/VMSA-2023-0012.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20887
Remediation Due Date: 2023-07-13
VMware
VMware Aria Operations for Networks updates address multiple vulnerabilities. (CVE-2023-20887, CVE-2023-20888, CVE-2023-20889)
vendor_vmware·2023-06-07·CVSS 9.8
CVE-2023-20887 [CRITICAL] VMware Aria Operations for Networks updates address multiple vulnerabilities. (CVE-2023-20887, CVE-2023-20888, CVE-2023-20889)
VMSA-2023-0012: VMware Aria Operations for Networks updates address multiple vulnerabilities. (CVE-2023-20887, CVE-2023-20888, CVE-2023-20889)
Aria Operations for Networks contains a command injection vulnerability. VMware has evaluated the severity of this issue to be in the critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2023-20887, CVE-2023-20888, CVE-2023-20889
Affected products: VMware Aria
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-10
Published