VYPR
Unrated severityNVD Advisory· Published Sep 6, 2012· Updated Apr 29, 2026

CVE-2011-5154

CVE-2011-5154

Description

Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.

Affected products

2
  • cpe:2.3:a:sap:graphical_user_interface:6.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:graphical_user_interface:6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:graphical_user_interface:7.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.