Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Security Note rfcexec/startrfc Used in File Interfaces, SAP security note 1140031

Description

Questions about the security of rfcexec and the RFC Library used in this context.

Available fix and Supported packages

  • KRNL32NUC | 6.40 | 6.40
  • KRNL32NUC | 7.00 | 7.01
  • KRNL32NUC | 7.10 | 7.10
  • KRNL32UC | 6.40 | 6.40
  • KRNL32UC | 7.00 | 7.01
  • KRNL32UC | 7.10 | 7.10
  • KRNL64NUC | 6.40 | 6.40
  • KRNL64NUC | 7.00 | 7.00
  • KRNL64NUC | 7.10 | 7.10
  • KRNL64UC | 6.40 | 6.40
  • KRNL64UC | 7.00 | 7.01
  • KRNL64UC | 7.10 | 7.10
  • SAP RFCSDK | 6.20 | 6.20
  • SAP RFCSDK | 6.40 | 6.40
  • SAP RFCSDK | 7.00 | 7.00
  • SAP RFCSDK | 7.10 | 7.10
  • NWRFCSDK | 7.10 | 7.10
  • SAP KERNEL 6.40 32-BIT | SP236 | 000236
  • SAP KERNEL 7.00 32-BIT | SP163 | 000163
  • SAP KERNEL 7.00 32-BIT UNICODE | SP163 | 000163
  • SAP KERNEL 7.00 64-BIT | SP163 | 000163
  • SAP KERNEL 7.00 64-BIT UNICODE | SP163 | 000163
  • SAP KERNEL 7.01 32-BIT | SP000 | 000000
  • SAP KERNEL 7.01 32-BIT | SP002 | 000002
  • SAP KERNEL 7.10 32-BIT | SP107 | 000107
  • SAP KERNEL 7.10 32-BIT UNICODE | SP107 | 000107
  • SAP KERNEL 7.10 64-BIT | SP107 | 000107
  • SAP KERNEL 7.10 64-BIT UNICODE | SP107 | 000107

Affected component

    BC-MID-RFC
    RFC

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1140031

TAGS

#Windows-rfcexec.exe
#startrfc.exe
#librfc32.dllSecurity-Advisory

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,