← Vulnerability feed

Vulnerability record · CVE-2007-3605 · published 6 July 2007

CVE-2007-3605: SAP GUI EnjoySAP ActiveX control stack buffer overflow

Sap · Enjoysap

The kweditcontrol.kwedit.1 ActiveX control in EnjoySAP SAP GUI (kwedit.dll) has a stack-based buffer overflow reachable through a long argument to the PrepareToPostHTML function. A remote attacker who can get the control instantiated in a browser can corrupt the stack and run code in the context of the logged-on user. The record is old and thin on affected version ranges, so scope must be confirmed against the vendor advisory.

7.6 CVSS 2.0 High EPSS 70% · top 0.6%
7.6CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with no authentication and public exploit code, tempered by the requirement that the victim load attacker content in a browser with the ActiveX control enabled.

What it is

The kweditcontrol.kwedit.1 ActiveX control in EnjoySAP SAP GUI (kwedit.dll) has a stack-based buffer overflow reachable through a long argument to the PrepareToPostHTML function. A remote attacker who can get the control instantiated in a browser can corrupt the stack and run code in the context of the logged-on user. The record is old and thin on affected version ranges, so scope must be confirmed against the vendor advisory.

Impact

Successful exploitation gives arbitrary code execution with the privileges of the user running the SAP GUI client, allowing full compromise of that workstation and any SAP sessions or credentials it holds.

Attack surface

Reached over the network via a crafted web page or HTML document that instantiates the ActiveX control and passes an oversized argument to PrepareToPostHTML; no authentication is required, but the victim must load the attacker's content in a browser that permits the control to run.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.699, 99.3rd percentile) and a public Exploit-DB entry plus a SecurityFocus reference tagged Exploit and Patch exist, indicating public exploit code and an available fix.

What to do

  • Apply the SAP patch referenced in the SecurityFocus advisory and upgrade EnjoySAP SAP GUI to a fixed release.
  • Kill-bit or block the kweditcontrol.kwedit.1 CLSID in Internet Explorer and restrict ActiveX execution in browsers on SAP client hosts.
  • Disable or unregister kwedit.dll where the control is not required for business use.
  • Limit browsing from SAP GUI workstations and enforce network controls so users cannot reach untrusted sites.
  • Track SAP GUI versions across the estate and confirm which hosts still carry the vulnerable control.

Detection

  • Search endpoint inventories and registry for the kweditcontrol.kwedit.1 CLSID and kwedit.dll under FrontEnd\SapGui.
  • Monitor browser and process telemetry for SAP GUI or browser processes loading kwedit.dll, especially after visits to untrusted sites.
  • Hunt for crashes or anomalous child processes spawned from SAP GUI or browser processes on client hosts.
  • Review proxy and DNS logs for access to known exploit-hosting or malicious pages from SAP client subnets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3605 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-3605), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.