Advisory
On 14.01.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAPSetup.
SAP Note 3542533 addresses "[CVE-2025-0069] DLL Hijacking vulnerability in SAPSetup" to prevent dll hijacking with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAPSetup allows an authenticated attacker with local user privileges or access to a compromised corporate Windows account to inject a malicious DLL, potentially escalating their privileges. This could enable the attacker to move laterally within the network and further compromise the company's Active Directory.Solution
The temporary directory is now created with the correct access permissions.