35423exploit
http://www.exploit-db.com/exploits/35423 CVE-2014-9141
Thomson Reuters Fixed Assets CS 13.1.4 - Local Privilege Escalation
Record summary
CVE-2014-9141 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBThomson Reuters Fixed Assets CS 13.1.4 - Local Privilege EscalationExploitDB exploitby Information ParadoxNot analyzed1 file
References
3information-paradox.net
http://www.information-paradox.net/2014/12/cve-2014-9141-thomson-reuters-fixed.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-9141