Record summary

CVE-2014-9141 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBThomson Reuters Fixed Assets CS 13.1.4 - Local Privilege EscalationExploitDB exploitby Information ParadoxNot analyzed1 file
ExploitDB

PoC details

References

3