SAP Security Note
High priority
SAP security note 1543318, "Potential Remote Termination of Kernel Processes", is a program error note released on April 12, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can remotely exploit kernel processes to terminate them manually.
Solution
Upgrade to the current kernel version as specified in the Validity section of the note.
Reason and prerequisites
The issue is caused by a memory corruption that forces the process to terminate. A malicious user can induce a condition where the process attempts to read outside its memory space, resulting in a memory protection fault. Consequently, the system terminates the process, rendering the application unusable until it is manually restarted.
References
Affected components
- KRNL32NUC
- KRNL32UC
- KRNL64NUC
- KRNL64UC
- KERNEL
Full note on SAP: SAP Support Launchpad note 1543318
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
