Executive brief
SAProuter, a software component used to connect SAP systems across different networks, contains a vulnerability when running on Microsoft Windows. An attacker can place a malicious file in a specific location on the system, which the software will then mistakenly load and run. If successful, this allows the attacker to take full control of the system, potentially leading to data theft, service disruption, or further unauthorized access to the corporate network.
Technical details
This vulnerability is classified as an Uncontrolled Search Path Element (CWE-427) within SAProuter running on Windows environments. The application fails to properly validate or restrict the search path used to load Dynamic Link Libraries (DLLs), allowing an attacker to perform DLL hijacking. By placing a malicious DLL in a directory searched by the application before the legitimate library, an attacker can achieve arbitrary code execution with the privileges of the SAProuter service. While the attack vector is local, it requires no prior authentication or user interaction. SAP has released security notes (3692165) to address this issue across multiple kernel and SAProuter versions.
Affected products
- SAP SE SAProuter on Microsoft Windows KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18
Timeline
- 2026-07-14: advisory: Initial publication by SAP and NVD