The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
References
Configurations
History
21 Nov 2024, 02:20
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.exploit-db.com/exploits/35423 - Exploit | |
References | () http://www.information-paradox.net/2014/12/cve-2014-9141-thomson-reuters-fixed.html - |
Information
Published : 2014-12-03 01:59
Updated : 2024-11-21 02:20
NVD link : CVE-2014-9141
Mitre link : CVE-2014-9141
CVE.ORG link : CVE-2014-9141
JSON object : View
Products Affected
thomsonreuters
- fixed_assets_cs
CWE
CWE-264
Permissions, Privileges, and Access Controls