← Vulnerability feed

Vulnerability record · CVE-2008-0621 · published 6 February 2008

CVE-2008-0621: SAP SAPLPD LPD command buffer overflow allows remote code execution

Sap · Sapgui

SAPLPD 6.28 and earlier, shipped with SAP GUI 7.10 and SAPSprint before 1018, contains a buffer overflow triggered by long arguments to LPD commands 0x01 through 0x05. Because the flaw is remotely reachable over the network without authentication, it exposes SAP print services to code execution attempts.

7.5 CVSS 2.0 High EPSS 73% · top 0.5% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with public exploit material and a very high EPSS score, though no confirmed active exploitation or KEV listing.

What it is

SAPLPD 6.28 and earlier, shipped with SAP GUI 7.10 and SAPSprint before 1018, contains a buffer overflow triggered by long arguments to LPD commands 0x01 through 0x05. Because the flaw is remotely reachable over the network without authentication, it exposes SAP print services to code execution attempts.

Impact

A remote attacker can execute arbitrary code in the context of the SAPLPD service, potentially taking over the host or pivoting into the SAP environment. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

Reached over the network via the LPD protocol (AV:N, AC:L, Au:N), so no authentication or user interaction is required. Any host exposing SAPLPD or SAPSprint LPD services is in scope.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.73359 (99.4th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Patch SAPLPD to a version later than 6.28 and SAPSprint to 1018 or later, or upgrade SAP GUI 7.10 to a fixed release.
  • If patching is not immediately possible, restrict network access to LPD ports to trusted print clients only.
  • Disable or stop the SAPLPD/SAPSprint service on hosts that do not require print spooling.
  • Segment print servers from general user and internet-facing networks.
  • Monitor vendor advisories for updated fixed versions before deploying.

Detection

  • Inspect LPD traffic for unusually long arguments to commands 0x01 through 0x05.
  • Alert on SAPLPD process crashes or unexpected restarts on print servers.
  • Monitor for unexpected child processes or outbound connections originating from SAPLPD/SAPSprint.
  • Review network logs for LPD connections from untrusted or external source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0621 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0620Sapgui memory buffer overflow vulnerabilitySAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LP…EPSS 3.3%9.3CVE-2007-4475Sapgui memory buffer overflow vulnerabilityStack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers t…EPSS 40%9.3CVE-2008-4387Sapgui code injection vulnerabilityUnspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk…EPSS 16%7.8CVE-2006-7220Saplpd vulnerabilityUnspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print jo…EPSS 1.2%7.5CVE-2016-10079Saplpd improper input validation vulnerabilitySAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.EPSS 6.5%7.5CVE-2003-1035Sap r 3 vulnerabilityThe default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a b…EPSS 1.5%5.0CVE-2002-1579Sapgui vulnerabilitySAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unkn…EPSS 1.6%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEVEPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2008-0621), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.