CVE-2023-32113: SAP GUI For Windows

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

Affected products

  • SAP GUI For Windows: before 7.70 (fixed in 7.70); version 7.70 only; version 8.0 only

Published 2023-05-09. Last modified 2026-06-17.