Privilege Escalation in SAP Adaptive Server Enterprise on Windows
CVE-2022-22528
7.8HIGH
Summary
A vulnerability exists in the SAP Adaptive Server Enterprise (ASE) version 16.0 installer for Windows, which adds an entry to the system PATH environment variable. This could potentially allow a Standard User to run malicious Windows binaries under specific circumstances, leading to privilege escalation on the local system. Notably, this issue is isolated to the ASE installer and does not affect other ASE binaries.
Affected Version(s)
SAP Adaptive Server Enterprise 16.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved