PT-2014-8846 · Thomson Reuters · Thomson Reuters Fixed Assets Cs

Singularitysec

·

Published

2014-12-03

·

Updated

2014-12-17

·

CVE-2014-9141

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Thomson Reuters Fixed Assets CS versions 13.1.4 and earlier
Description The issue concerns weak permissions set by the installer for the connectgdll.exe program, allowing local users to execute arbitrary code by modifying this program.
Recommendations For versions 13.1.4 and earlier, consider restricting access to the connectgdll.exe program to prevent local users from modifying it until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9141

Affected Products

Thomson Reuters Fixed Assets Cs