### [CVE-2020-6234](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6234) ![](https://img.shields.io/static/v1?label=Product&message=SAP%20Host%20Agent&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C7.21%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Privilege%20Escalation&color=brighgreen) ### Description SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating system, leading to Privilege Escalation. ### POC #### Reference - http://packetstormsecurity.com/files/162084/SAP-Host-Control-Local-Privilege-Escalation.html - http://packetstormsecurity.com/files/162084/SAP-Host-Control-Local-Privilege-Escalation.html #### Github - https://github.com/Onapsis/vulnerability_advisories - https://github.com/lmkalg/my_cves