CVE-2025-42943
Last modified
CVE-2025-42943 is a medium-severity vulnerability rated 4.5/10 on the CVSS scale. SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP GUI for Windows. This could trigger automatic NTLM authentication, potentially exposing hashed credentials to an attacker. As a result, it has a high impact on the confidentiality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-42943?
How severe is CVE-2025-42943?
How do I fix CVE-2025-42943?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-42938Due to a Cross-Site Scripting (XSS) vulnerability in the SAP…6.1
- CVE-2025-42939SAP S/4HANA (Manage Processing Rules - For Bank Statements) …4.3
- CVE-2025-4294Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-42940SAP CommonCryptoLib does not perform necessary boundary chec…7.5
- CVE-2025-42941SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vu…3.5
- CVE-2025-42942SAP NetWeaver Application Server for ABAP has cross-site scr…6.1
- CVE-2025-42944Due to a deserialization vulnerability in SAP NetWeaver, an …10
- CVE-2025-42945SAP NetWeaver Application Server ABAP has HTML injection vul…6.1
- CVE-2025-42946Due to directory traversal vulnerability in SAP S/4HANA (Ban…6.9
- CVE-2025-42947SAP FICA ODN framework allows a high privileged user to inje…5.5
- CVE-2025-42948Due to a Cross-Site Scripting (XSS) vulnerability in SAP Net…6.1
- CVE-2025-42949Due to a missing authorization check in the ABAP Platform, a…4.9
Are you affected by CVE-2025-42943?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
