PT-2014-8846 · Thomson Reuters · Thomson Reuters Fixed Assets Cs
Singularitysec
·
Published
2014-12-03
·
Updated
2014-12-17
·
CVE-2014-9141
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Thomson Reuters Fixed Assets CS versions 13.1.4 and earlier
Description
The issue concerns weak permissions set by the installer for the connectgdll.exe program, allowing local users to execute arbitrary code by modifying this program.
Recommendations
For versions 13.1.4 and earlier, consider restricting access to the connectgdll.exe program to prevent local users from modifying it until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thomson Reuters Fixed Assets Cs