Record summary

CVE-2014-9113 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCCH Wolters Kluwer PFX Engagement 7.1 - Local Privilege EscalationExploitDB exploitby Information ParadoxNot analyzed1 file
ExploitDB

PoC details

References

4