7.5
CVSSv2

CVE-2019-8385

Published: 05/06/2019 Updated: 06/06/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote malicious user to list or enumerate sensitive contents of files via a \.. to port 6677. Additionally, this could allow for privilege escalation by dumping the affected machine's SAM and SYSTEM database files, as well as remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thomsonreuters concourse matter room

thomsonreuters firm central desktop

Exploits

''' # Exploit Title: Thomson Reuters Concourse & Firm Central < 2130097 - Directory Traversal & Local File Inclusion # Date: 02/13/2019 # Exploit Author: 0v3rride # Vendor Homepage: wwwthomsonreuterscom/enhtml # Software Link: Firm Central (infolegalsolutionsthomsonreuterscom/software/firm-central/defaultaspx) &a ...

Github Repositories

PoCs PoCs for most of the zero days that I've discovered: CVE-2019-6716 - No - Unauthenticated IDOR CVE-2019-7751 - Yes - Directory Traversal & LFI CVE-2019-8385 - Yes - Directory Traversal & LFI