CVE-2024-47576: DLL Hijacking vulnerability in SAP Product Lifecycle Costing
SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being part of SAP Product Lifecycle Costing Client Application. On a successful attack, it can cause a low impact to confidentiality but no impact to the integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47576?
CVE-2024-47576 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-47576?
To mitigate CVE-2024-47576, update the SAP Product Lifecycle Costing Client to version 4.7.1 or later.
What types of attacks could exploit CVE-2024-47576?
CVE-2024-47576 could be exploited through DLL hijacking attacks, allowing attackers to execute malicious code.
Which versions of SAP Product Lifecycle Costing Client are affected by CVE-2024-47576?
CVE-2024-47576 affects all versions of SAP Product Lifecycle Costing Client below 4.7.1.
Is there a workaround for CVE-2024-47576?
Currently, there is no official workaround for CVE-2024-47576 other than upgrading to a secured version.