Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential remote termination of running processes in kernel, SAP security note 1543318

SAP Note 1543318
SAP Security Note
High priority

SAP security note 1543318, "Potential Remote Termination of Kernel Processes", is a program error note released on April 12, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Middleware > RFC (BC-MID-RFC)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onApril 12, 2011
LanguageEnglish

Description

Symptom

A malicious user can remotely exploit kernel processes to terminate them manually.

Solution

Upgrade to the current kernel version as specified in the Validity section of the note.

Reason and prerequisites

The issue is caused by a memory corruption that forces the process to terminate. A malicious user can induce a condition where the process attempts to read outside its memory space, resulting in a memory protection fault. Consequently, the system terminates the process, rendering the application unusable until it is manually restarted.

References

Affected components

  • KRNL32NUC
  • KRNL32UC
  • KRNL64NUC
  • KRNL64UC
  • KERNEL

Full note on SAP: SAP Support Launchpad note 1543318

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More