NTLM Hash Exposure in SAP GUI for Windows by SAP
CVE-2025-42943
4.5MEDIUM
What is CVE-2025-42943?
The SAP GUI for Windows is susceptible to a vulnerability that may lead to the leakage of NTLM hashes when certain ABAP frontend services are accessed using UNC paths. Successful exploitation demands that an attacker possess developer authorization on a targeted Application Server ABAP and that the victim unwittingly initiates operations through the SAP GUI for Windows. This scenario may automatically engage NTLM authentication, potentially allowing adversaries to capture hashed credentials, thereby threatening sensitive data confidentiality.
Affected Version(s)
SAP GUI for Windows BC-FES-GUI 8.00