LiveActive security incident?Get immediate response
CVE Record

CVE-2021-45492: In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime direc...

In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this directory is writable by unprivileged users because the Sage installer fails to set explicit permissions and therefore inherits weak permissions from the C:\ folder. Because entries in the system-wide PATH variable are included in the search order for DLLs, an attacker could perform DLL search-order hijacking to escalate their privileges to SYSTEM. Furthermore, if the Global Search or Web Screens functionality is enabled, then privilege escalation is possible via the GlobalSearchService and Sage.CNA.WindowsService services, again via DLL search-order hijacking because unprivileged users would have modify permissions on the application directory. Note that while older versions of the software default to installing in %PROGRAMFILES(X86)% (which would allow the Sage folder to inherit strong permissions, making the installation not vulnerable), the official Sage 300 installation guides for those versions recommend installing in C:\Sage, which would make the installation vulnerable.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Some Sage 300 ERP installations place a Sage runtime folder first in Windows' system PATH while allowing ordinary users to write there. That can let a local attacker influence what privileged Sage or Windows service processes load, potentially gaining SYSTEM privileges.

Executive priority

Treat this as a high-priority hardening issue for Sage 300 servers because compromise by a local user could become full system control. Prioritize shared application servers and environments where many users have local access.

Technical view

CVE-2021-45492 is a DLL search-order hijacking issue in Sage 300 ERP through 6.8.x. The installer may put C:\Sage\Sage300\Runtime first in the system PATH, and C:\Sage installations can inherit weak write permissions. Global Search or Web Screens services add exposure when enabled.

Likely exposure

Most relevant to Windows hosts running Sage 300 ERP through 6.8.x installed under C:\Sage or another writable application path. Installations under %PROGRAMFILES(X86)% with strong inherited permissions may not be affected based on the source description.

Exploitation context

The provided sources support local privilege escalation to SYSTEM through DLL search-order hijacking. They do not state internet-facing remote exploitation, public weaponization, or active exploitation. The CVE is not listed as KEV in the supplied bundle.

Researcher notes

Evidence is strongest for misconfigured install paths and inherited ACLs, not for a universal product defect across all installs. The source bundle lacks CVSS, CWE mapping, patch details, and proof of active exploitation.

Mitigation direction

  • Check Sage guidance for supported fixes or configuration changes.
  • Restrict write access to C:\Sage\Sage300\Runtime and Sage application directories.
  • Remove user-writable directories from early system-wide PATH positions.
  • Disable Global Search or Web Screens where unnecessary until permissions are fixed.
  • Review Sage 300 version and installation path against vendor documentation.

Validation and detection

  • Identify Sage 300 ERP hosts and confirm installed version.
  • Check whether C:\Sage\Sage300\Runtime is first in system PATH.
  • Verify unprivileged users cannot modify Sage runtime directories.
  • Confirm GlobalSearchService and Sage.CNA.WindowsService status on affected hosts.
  • Document exceptions for installations inheriting strong Program Files permissions.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Privilege behavior lookup

The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-45492 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.