PT-2014-8833 · Wolters Kluwer · Cch Wolters Kluwer Prosystem Fx Engagement

Singularitysec

·

Publicado

2014-12-02

·

Atualizado

2014-12-15

·

CVE-2014-9113

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) versions 7.1 and earlier
Description The issue concerns weak permissions for certain service files, specifically Pfx.Engagement.WcfServices, PFXEngDesktopService, PFXSYNPFTService, and P2EWinService, which are set to allow Authenticated Users to modify and write. This weakness can be exploited by local users to gain LocalSystem privileges through the use of a Trojan horse file.
Recommendations For versions 7.1 and earlier, consider restricting the permissions of the service files Pfx.Engagement.WcfServices, PFXEngDesktopService, PFXSYNPFTService, and P2EWinService to prevent unauthorized modifications. As a temporary workaround, monitor these files closely for any suspicious activity until a more permanent solution is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9113

Produtos afetados

Cch Wolters Kluwer Prosystem Fx Engagement