Vulnerability record · CVE-2008-0621 · published 6 February 2008
CVE-2008-0621: SAP SAPLPD LPD command buffer overflow allows remote code execution
Sap · Sapgui
SAPLPD 6.28 and earlier, shipped with SAP GUI 7.10 and SAPSprint before 1018, contains a buffer overflow triggered by long arguments to LPD commands 0x01 through 0x05. Because the flaw is remotely reachable over the network without authentication, it exposes SAP print services to code execution attempts.
Description
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit material and a very high EPSS score, though no confirmed active exploitation or KEV listing.
What it is
SAPLPD 6.28 and earlier, shipped with SAP GUI 7.10 and SAPSprint before 1018, contains a buffer overflow triggered by long arguments to LPD commands 0x01 through 0x05. Because the flaw is remotely reachable over the network without authentication, it exposes SAP print services to code execution attempts.
Impact
A remote attacker can execute arbitrary code in the context of the SAPLPD service, potentially taking over the host or pivoting into the SAP environment. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached over the network via the LPD protocol (AV:N, AC:L, Au:N), so no authentication or user interaction is required. Any host exposing SAPLPD or SAPSprint LPD services is in scope.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.73359 (99.4th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Patch SAPLPD to a version later than 6.28 and SAPSprint to 1018 or later, or upgrade SAP GUI 7.10 to a fixed release.
- If patching is not immediately possible, restrict network access to LPD ports to trusted print clients only.
- Disable or stop the SAPLPD/SAPSprint service on hosts that do not require print spooling.
- Segment print servers from general user and internet-facing networks.
- Monitor vendor advisories for updated fixed versions before deploying.
Detection
- Inspect LPD traffic for unusually long arguments to commands 0x01 through 0x05.
- Alert on SAPLPD process crashes or unexpected restarts on print servers.
- Monitor for unexpected child processes or outbound connections originating from SAPLPD/SAPSprint.
- Review network logs for LPD connections from untrusted or external source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0621 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0621), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.