CVE-2023-29187: SAP Sapsetup
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various preconditions beyond the attackers control.
Affected products
- SAP Sapsetup: version 9.0 only
Published 2023-04-11. Last modified 2026-06-17.