Vulnerability record · CVE-2007-3605 · published 6 July 2007
CVE-2007-3605: SAP GUI EnjoySAP ActiveX control stack buffer overflow
Sap · Enjoysap
The kweditcontrol.kwedit.1 ActiveX control in EnjoySAP SAP GUI (kwedit.dll) has a stack-based buffer overflow reachable through a long argument to the PrepareToPostHTML function. A remote attacker who can get the control instantiated in a browser can corrupt the stack and run code in the context of the logged-on user. The record is old and thin on affected version ranges, so scope must be confirmed against the vendor advisory.
Description
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with no authentication and public exploit code, tempered by the requirement that the victim load attacker content in a browser with the ActiveX control enabled.
What it is
The kweditcontrol.kwedit.1 ActiveX control in EnjoySAP SAP GUI (kwedit.dll) has a stack-based buffer overflow reachable through a long argument to the PrepareToPostHTML function. A remote attacker who can get the control instantiated in a browser can corrupt the stack and run code in the context of the logged-on user. The record is old and thin on affected version ranges, so scope must be confirmed against the vendor advisory.
Impact
Successful exploitation gives arbitrary code execution with the privileges of the user running the SAP GUI client, allowing full compromise of that workstation and any SAP sessions or credentials it holds.
Attack surface
Reached over the network via a crafted web page or HTML document that instantiates the ActiveX control and passes an oversized argument to PrepareToPostHTML; no authentication is required, but the victim must load the attacker's content in a browser that permits the control to run.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.699, 99.3rd percentile) and a public Exploit-DB entry plus a SecurityFocus reference tagged Exploit and Patch exist, indicating public exploit code and an available fix.
What to do
- Apply the SAP patch referenced in the SecurityFocus advisory and upgrade EnjoySAP SAP GUI to a fixed release.
- Kill-bit or block the kweditcontrol.kwedit.1 CLSID in Internet Explorer and restrict ActiveX execution in browsers on SAP client hosts.
- Disable or unregister kwedit.dll where the control is not required for business use.
- Limit browsing from SAP GUI workstations and enforce network controls so users cannot reach untrusted sites.
- Track SAP GUI versions across the estate and confirm which hosts still carry the vulnerable control.
Detection
- Search endpoint inventories and registry for the kweditcontrol.kwedit.1 CLSID and kwedit.dll under FrontEnd\SapGui.
- Monitor browser and process telemetry for SAP GUI or browser processes loading kwedit.dll, especially after visits to untrusted sites.
- Hunt for crashes or anomalous child processes spawned from SAP GUI or browser processes on client hosts.
- Review proxy and DNS logs for access to known exploit-hosting or malicious pages from SAP client subnets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3605 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3605), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.