7.2
CVSSv2

CVE-2014-9141

Published: 03/12/2014 Updated: 17/12/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The installer in Thomson Reuters Fixed Assets CS 13.1.4 and previous versions uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.

Vulnerable Product Search on Vulmon Subscribe to Product

thomsonreuters fixed assets cs

Exploits

# Exploit Title: Thomson Reuters Fixed Assets CS <=1314 Local Privilege Escalation/Code Execution # Date: 12/1/14 # Exploit Author: singularitysec@gmailcom # Vendor Homepage: csthomsonreuterscom # Version: Fixed Assets CS <=1314 Local Privilege Escalation/Code Execution # Tested on: Windows XP -> Windows 7, Windows 8 ...