7.2
CVSSv2

CVE-2014-9113

Published: 02/12/2014 Updated: 15/12/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and previous versions uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cchgroup prosystem fx engagement

Exploits

# Exploit Title: CCH Wolters Kluwer PFX Engagement <= v71 Local Privilege Escalation # Date: 11/26/14 # Exploit Author: singularitysec@gmailcom # Vendor Homepage: wwwcchgroupcom # Version: PFX Engagement <= v71 # Tested on: Windows XP -> Windows 8, 2003, 2008, 2012 # CVE : 2014-9113 Product Affected: CCH Wolters Kluwer PFX Engage ...