CVE-2025-0069: SAP SE Sapsetup

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server.

Affected products

Published 2025-01-14. Last modified 2026-06-17.