Gui For Windows
Vendor:
First CVE: Mar 23, 2017 · Active for 9 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gui For Windows over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2017
9 years ago
Most Recent CVE
Jul 9, 2024
745 days ago
CVE Severity & Scoring
Gui For Windows5 CVEs
40%
20%
40%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (40.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low1 (20.0%)
High1 (20.0%)
None3 (60.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6950CRITICAL SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616. | Mar 23, 2017 | 9.8 | 32 | NO | NO |
CVE-2023-32113CRITICAL SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. | May 9, 2023 | 9.3 | 28 | NO | NO |
CVE-2021-40503HIGH An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side | Nov 10, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-27612MEDIUM In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishi | May 11, 2021 | 6.1 | 20 | NO | NO |
CVE-2024-39600MEDIUM Under certain conditions, the memory of SAP GUI
for Windows contains the password used to log on to an SAP system, which might
allow an attacker to get hold of the password and imp | Jul 9, 2024 | 4.2 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Gui For Windows
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 2 | 7.6 | 0.4% | 0 | 0 |
| 7.70 | 3 | 8.8 | 0.5% | 0 | 0 |
| 7.60 | 2 | 7.0 | 0.4% | 0 | 0 |
| 7.50_core_sp000 | 1 | 9.8 | 3.8% | 0 | 0 |
| 7.40_core_sp00-sp011 | 1 | 9.8 | 3.8% | 0 | 0 |
| 7.30 | 1 | 9.8 | 3.8% | 0 | 0 |
| 7.20 | 1 | 9.8 | 3.8% | 0 | 0 |